URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/hMSkZgr1VlC14nT.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3662848
URL: http://91.92.240.104/hMSkZgr1VlC14nT.exe
URL Status:flame Online (spreading malware for 1 month, 15 days, 11 hours, 58 minutes)
Host: 91.92.240.104
Date added:2025-10-07 19:15:07 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-10-07 19:16:15 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-10hMSkZgr1VlC14nT.exeexe 463042e3240530efc353db43b345472b91415d2a45c8e79d8815ba620bee9172Virustotal results 38.33% MassLogger
2025-10-08hMSkZgr1VlC14nT.exeexe c281815e1c5df268089f34c5cc30ae757db1f022d13b3ea0718e29b00584a8feVirustotal results 41.67% MassLogger
2025-10-08hMSkZgr1VlC14nT.exeexe dffefe7baf04a2b2207fc68ae301f535db991cf0b00972ff8f2bb02e70eee302Virustotal results 29.17% MassLogger
2025-10-07hMSkZgr1VlC14nT.exeexe dc8856f9b6ef81442715fa7dc861932df7c99bc43e9377d712927bf0ba874357n/aMassLogger