FILEMembers
FILE

Two distinct Windows files share the same executable URL

Network-rule matches for two differently packaged Windows files name the exact same executable URL, making it a concrete delivery lead. The records do not show that the files obtained the same binary or belonged to a single execution chain.

Oct 5, 2026, 15:26 (UTC+9)Last seenOct 5, 2026Severity100ByCTX TeamActorLazarus GroupHastati GroupIOC38RegionsUS

The same executable URL, http://propanla.com/77.exe, appears in network-rule matches associated with two distinct Windows files: one carrying 7-Zip self-extractor metadata, the other identifying its product as FarLabUninstaller. The shared address raises a concrete question: does it connect two stages of a delivery chain, or show separate files reaching the same delivery location? CTX Threat Intelligence’s records support the second, narrower finding.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence