URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/AFkzsPYF66VLCjs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3662850
URL: http://91.92.240.104/AFkzsPYF66VLCjs.exe
URL Status:flame Online (spreading malware for 1 month, 15 days, 11 hours, 56 minutes)
Host: 91.92.240.104
Date added:2025-10-07 19:16:07 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-10-07 19:17:14 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-10AFkzsPYF66VLCjs.exeexe 0335500b3ecb20cb6d501f6bf2640d811cf267bc63067edb130a9c6180836623Virustotal results 47.06% MassLogger
2025-10-08AFkzsPYF66VLCjs.exeexe c6ff610f69a805da190a7a8db8271e6f02008396681a4af531f2acd7ff198a7aVirustotal results 41.67% MassLogger
2025-10-08AFkzsPYF66VLCjs.exeexe 1d4ca2ce7227cfed8f34c4adcc1dd70d579ff95f909e109f1246a6801033bd83Virustotal results 26.39% MassLogger
2025-10-07AFkzsPYF66VLCjs.exeexe fb2b445ef7f400976f11b93dbe1c1cd655e9c1288fa125aa7ead3e3bed483118n/aMassLogger