URLhaus Database

You are currently viewing the URLhaus database entry for http://77.83.39.185/shel/fros/ENCRYPTED.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3766134
URL: http://77.83.39.185/shel/fros/ENCRYPTED.ps1
URL Status:flame Online (spreading malware for 5 days, 13 hours, 24 minutes)
Host: 77.83.39.185
Date added:2026-01-30 12:47:06 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-02-02 01:18:10 UTC to abuse{at}lanedo[dot]net)
Tags:ascii opendir PhantomStealer powershell ps1

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-04ENCRYPTED.ps1ps1 4a34e6614acd4a138eb1f308c21be91a8f0c53f00c307a1a5cf2a178182b62c4n/aPhantomStealer
2026-02-03ENCRYPTED.ps1ps1 c0b1fa407b6f1c7a2c0636febc35adf5494f887dd5001be9bd5fab0870ad2ecdn/aPhantomStealer
2026-02-03ENCRYPTED.ps1ps1 f27fcf6c0186768380cb60cba7410148a51c84edbe94535f2c9fcb5af464b40bn/a 
2026-02-02ENCRYPTED.ps1ps1 379b7783b0ad1be91022dbfeb8d4159738968898e7c1375aade28b8bd6ecc669n/a