URLhaus Database

You are currently viewing the URLhaus database entry for http://185.100.157.111/122.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3693198
URL: http://185.100.157.111/122.exe
URL Status:Offline
Host: 185.100.157.111
Date added:2025-11-01 11:58:06 UTC
Last online:2025-11-04 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-11-01 11:59:13 UTC to abuse{at}altawk[dot]com)
Takedown time:3 days, 5 hours, 22 minutes Bad (down since 2025-11-04 17:21:33 UTC)
Tags:dropped-by-amadey ecd247 PureLogsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-03122.exeexe 1b6d25731a21bfd4f09b58a0b72f8c2f72b272e009c2015874354e7d8f64a35fVirustotal results 63.38%
2025-11-01122.exeexe 48f721bd8e1dc590ebc195df91244a2053fe0d691767f067814c7ec658eb4ec9Virustotal results 50.70% PureLogsStealer
2025-11-01122.exeexe ebdabdfc98824addcb4d5160fdb4efc9b18ffd7464cf4d40d08977b21d635f8dn/a