URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/fcPgnRwkCjpeOjh.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3661438
URL: http://91.92.240.104/fcPgnRwkCjpeOjh.exe
URL Status:flame Online (spreading malware for 1 month, 15 days, 16 hours, 25 minutes)
Host: 91.92.240.104
Date added:2025-10-07 14:48:07 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-10-07 14:49:12 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-10fcPgnRwkCjpeOjh.exeexe 941f2a792b6659ede86ca3d56ddd2e6f3d1b44ac0eec03a2e6b351374048f734Virustotal results 45.83% MassLogger
2025-10-08fcPgnRwkCjpeOjh.exeexe 14294c325dd42780898285aa3b1129bb65c6f3503887d06443acdec16e180d64Virustotal results 40.28% MassLogger
2025-10-08fcPgnRwkCjpeOjh.exeexe 65a53e12c4e8234cd763add1392ccf7d4365da8c77cf3e23dd72355d67e9abaaVirustotal results 26.39% MassLogger
2025-10-07fcPgnRwkCjpeOjh.exeexe befaf5e220057a7072526b655ee11e81d7fa9c46b6597cc61e4d5ba659cfd191Virustotal results 34.72% MassLogger
2025-10-07fcPgnRwkCjpeOjh.exeexe c3f65559fab1f1f3ce2fce0f867ba08de4533aa6c856cb6469bfb5e6f3699867n/a MassLogger