URLhaus Database

You are currently viewing the URLhaus database entry for http://83.142.209.75:751/download which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3823636
URL: http://83.142.209.75:751/download
URL Status:flame Online (spreading malware for 10 days, 22 hours, 9 minutes)
Host: 83.142.209.75
Date added:2026-04-16 11:45:43 UTC
Threat:Malware download Malware download
Reporter: burger
Abuse complaint sent (?): Yes (2026-04-16 11:46:24 UTC to 83abuse{at}demenin[dot]net,abuse{at}demenin[dot]net)
Tags:exe RapidStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-26ChatAgent.exeexe 068fdc468cbe5e83f1fb4fc1fc5da32a92db0a193143fa0b85ee9eab4d84ade0n/a 
2026-04-19ChatAgent.exeexe 671b028033d4123f85d64c3c60ccf1f3057bf1e80b3189a355950ba6144ad256n/aRapidStealer
2026-04-18ChatAgent.exeexe 947b29a977f4690909c63d5c3fa89585c508549be4c5e1b3f2c3d051d42dfaaen/a 
2026-04-16ChatAgent.exeexe aa589ef7e0ea27bed4ee87929117cfc5b28b68c343b3991209514db311c1a3ecn/aRapidStealer