URLhaus Database

You are currently viewing the URLhaus database entry for http://80.89.224.210/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3805375
URL: http://80.89.224.210/1.exe
URL Status:Offline
Host: 80.89.224.210
Date added:2026-03-26 08:51:09 UTC
Last online:2026-03-27 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-03-26 08:52:11 UTC to abuse{at}novoserve[dot]com,abuse{at}server-panel[dot]net)
Takedown time:1 day, 6 hours, 16 minutes Poor (down since 2026-03-27 15:08:22 UTC)
Tags:c2-monitor-auto dropped-by-amadey Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-271.exeexe 593efd69810e81ed7ea248e2f4482120d64dad18911f789e79c498a0c54cfd5bn/a Vidar
2026-03-271.exeexe 24901292e1d8a13747d0c509d7b9e1021334b7f2dcfc4e5283357b104399ba88n/a Vidar
2026-03-271.exeexe 8935a3453ec261aea37a35f367e1ed599d40c6f1de108dd9c06e6b259c81bd2en/a Vidar
2026-03-261.exeexe 7150d5090a349673dd3d6ac39aa299dc255bdefaebf680da4fc99c1a2cfa9112n/a Vidar
2026-03-261.exeexe 49adafb6a2d57ae2e4dc7503ed9cfc6c87deec42efa4f5256a5338c0b8f45bbbn/a Vidar
2026-03-261.exeexe 58d19dff2088c16551f74b2814d490ce37cf21dbd42cb5278473bbe2c31aec8fn/a Vidar
2026-03-261.exeexe 1921813bfdd84598f4240c271d29e112482896f63427636d0601b0f599410f0bn/aVidar