URLhaus Database

You are currently viewing the URLhaus database entry for http://188.137.245.221/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3790121
URL: http://188.137.245.221/1.exe
URL Status:flame Online (spreading malware for 1 day, 22 hours, 8 minutes)
Host: 188.137.245.221
Date added:2026-03-05 14:02:16 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-03-05 14:03:13 UTC to abuse{at}podaon[dot]com)
Tags:c2-monitor-auto dropped-by-amadey Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-071.exeexe 7e1f3c8af73a8faa59ffdcdbff3063a6f7d2c038c295bd862f8b0e98c1fc6811n/a 
2026-03-071.exeexe 2c871a66caa73566559e61c3340a44f74c0e4000f25a421f8051139d475c798cn/a 
2026-03-061.exeexe 9c3403d685fe924217c09602a40be9616f3ead932c428338c6e3c7a22c2a6029n/a 
2026-03-061.exeexe b66ac3173197422685c3b1952a80c8cca477ddc50d3fa97f8b1cd5a35801eb18n/a Vidar
2026-03-061.exeexe 0c570f5470bb933eaa87438d498b7793df1fcd3962b7896e73042f87efa89f73n/a Vidar
2026-03-061.exeexe 2353b4464da210b5f6a62a1b6d4022dffcb2a8d50beaacffc5bdd446b2370aadn/a Vidar
2026-03-061.exeexe 674b2f14259eb38bbb532b269d9e6e861669bf362fc4b5ab523d0452ac3ee87bn/a Vidar
2026-03-051.exeexe 750d0077d8036c6ce10c3273d4d056a460195e9782c4dd0a7a18056352a14689n/a Vidar
2026-03-051.exeexe 98b7a56a3f1b4691d3244fdcc4da8106b8b31caa2cf787e9e45b2b72aef0b05dn/aVidar