URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/3nxW7k1nAOzhQuf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3635763
URL: http://91.92.240.104/3nxW7k1nAOzhQuf.exe
URL Status:flame Online (spreading malware for 1 month, 21 days, 6 hours, 14 minutes)
Host: 91.92.240.104
Date added:2025-09-30 15:10:08 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-30 15:11:15 UTC to abuse{at}metaspinner[dot]net)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-023nxW7k1nAOzhQuf.exeexe cc9cbdb14182ce0d118ebca0da8860ffbc78708c1583a62652cfcb0a8ecf42d8Virustotal results 37.50% Loki
2025-10-013nxW7k1nAOzhQuf.exeexe 3466c5a661b5cecf8230e948feba54ae8145891f0a1fb626aedc6d17a0abf450Virustotal results 33.33% Loki
2025-09-303nxW7k1nAOzhQuf.exeexe e70fdec083ef8fc4fc697f56e1d7e5aea5684083e4123c6df382df80be2c1c45Virustotal results 32.39%Loki
2025-09-303nxW7k1nAOzhQuf.exeexe 5f6f593e7ab45cfbef33f249eaadc2eb0e29b752a8d517d8793b6dc5f534dce8Virustotal results 36.11%Loki