URLhaus Database

You are currently viewing the URLhaus database entry for https://mgtms.cc/force/Win_Driver_SSL_support_v43.22.209.44.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3789365
URL: https://mgtms.cc/force/Win_Driver_SSL_support_v43.22.209.44.exe
URL Status:flame Online (spreading malware for 21 days, 10 hours, 44 minutes)
Host: mgtms.cc
Date added:2026-03-04 06:10:14 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Botnet C&C domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-03-04 06:11:14 UTC to abuse{at}kyonix[dot]com)
Tags:ACRStealer AmateraStealer exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19Win_Driver_SSL_support_v43.22.209.44.exeexe 5c81dcd6c3824436c1997ed858bf562e5d97584d14a88269f1553d211cdd9e15n/aACRStealer
2026-03-18Win_Driver_SSL_support_v43.22.209.44.exeexe 95bd1788ff3ce7d8f0ad6a379187bafaca59216e6c3d0b7583608d0f17eede0bn/a ACRStealer
2026-03-16Win_Driver_SSL_support_v43.22.209.44.exeexe e15de690855cd23361af69a71b60d4299328582e2772b6eb25a3cc96617a8f59n/aACRStealer
2026-03-10Win_Driver_SSL_support_v43.22.209.44.exeexe a39eca46f834e874975e46eeda652906ab3576735fe930cec7e284560c6145can/aAmateraStealer
2026-03-05Win_Driver_SSL_support_v43.22.209.44.exeexe 9b153b3fda8915bc1e3de3969fb7d23414886dda0e0fb6aa915caaa01be370bcn/aACRStealer
2026-03-05Win_Driver_SSL_support_v43.22.209.44.exeexe 903e3b20852eb6b2981336d045befc77286299d461af10658b68b20912d00c00n/aAmateraStealer
2026-03-04Win_Driver_SSL_support_v43.22.209.44.exeexe fc0679e7f8653a35bb725adfd54fa7a58db8b1d10ef0231c65907db622075b58n/aAmateraStealer