URLhaus Database

You are currently viewing the URLhaus database entry for http://150.241.65.48/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740768
URL: http://150.241.65.48/1.exe
URL Status:flame Online (spreading malware for 3 days, 17 hours, 20 minutes)
Host: 150.241.65.48
Date added:2025-12-23 03:12:09 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-12-23 03:13:13 UTC to abuse{at}biil[dot]ru)
Tags:c2-monitor-auto dropped-by-amadey Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-241.exeexe c10fa9d1c08603b40c12d485d9efe158df40c0ab3c0af8b9da6b433367057de5n/a
2025-12-241.exeexe ce5686bbb9237dab398663fd30c7b339bf7115e288de5ae4a07b137d393da629n/a
2025-12-231.exeexe 1763df05d8308948c1ed4489c727a31832951f63e26ae895e0cc0fba75cee9afn/aStealc