URLhaus Database

You are currently viewing the URLhaus database entry for http://80.89.238.200/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3793120
URL: http://80.89.238.200/1.exe
URL Status:Offline
Host: 80.89.238.200
Date added:2026-03-09 15:18:19 UTC
Last online:2026-03-10 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-09 15:19:12 UTC to abuse{at}server-panel[dot]net)
Takedown time:1 day, 5 hours, 18 minutes Poor (down since 2026-03-10 20:38:07 UTC)
Tags:dropped-by-amadey fbf543 Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-101.exeexe bf4e59777baeab7c668aa1c791f565fda213d1d31c71ba8cf0ee28e937fa6ab4n/aVidar
2026-03-101.exeexe df60864b5641a99c2ca275e6d65d117153522d045cd2b033eb3b669ea88a1370n/a Vidar
2026-03-101.exeexe 1b09b4cfc1d7fd42d141ca7460d602566708235268c8f49de26e748f9a819538n/a Vidar
2026-03-101.exeexe 4a5b6bf84be251f43cdc4f36aa559dd1fcf75f9b8c8ae45c5030c2fb3ceb5b3an/a Vidar
2026-03-091.exeexe 86325f5ba919a178171c5825d7f7b6db6619600bc4c041114b82ac2cde0ea2b4n/a 
2026-03-091.exeexe 7d3f3b8966fd945285d4ba2bacb706c4b47e4ffb9c84ee4264660d89a5232192n/aVidar