URLhaus Database

You are currently viewing the URLhaus database entry for http://178.157.91.246/a14.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:853278
URL: http://178.157.91.246/a14.exe
URL Status:Offline
Host: 178.157.91.246
Date added:2020-11-25 13:08:04 UTC
Last online:2020-11-27 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-25 13:10:03 UTC to abuse{at}mvps[dot]net)
Takedown time:1 day, 23 hours, 1 minutes Poor (down since 2020-11-27 12:11:45 UTC)
Tags:exe TaurusStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-26n/aexe 16995e059eb47de0b58a95ce2c3d863d964a7a16064d4298cee9db1de266e68dn/aTaurusStealer
2020-11-25n/aexe 68f9243f40945d2c3f15bed2d106401737caa94a26716af3d5918b3c0f760e8bn/aTaurusStealer
2020-11-25n/aexe 100f3322fa66d60cb9a64e2cbcceb0a9558e65e600526fcbc25852d62940c7eaVirustotal results 43.66%TaurusStealer