URLhaus Database

You are currently viewing the URLhaus database entry for http://222.211.72.29:35641/gz.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1813898
URL: http://222.211.72.29:35641/gz.exe
URL Status:Offline
Host: 222.211.72.29
Date added:2021-11-24 19:45:09 UTC
Last online:2021-11-26 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-26 05:12:05 UTC to anti-spam{at}ns[dot]chinanet[dot]cn[dot]net)
Takedown time:1 month, 3 days, 13 hours, 51 minutes Bad (down since 2021-12-28 09:37:43 UTC)
Tags:32 exe Hupigon

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-01gz.exeexe 1d77d936dd1e201c39e913329716de6eaffb8cf2e070322d1a02130597597fedn/a 
2021-12-01gz.exeexe 553af5272ca7bceb01006ef67fdff013dee163325f0da9da0192300eaed42858n/a 
2021-12-01gz.exeexe 8a56bbb9442016d1a6f51455b7c0014f6d38cf42af82e741d4a3c62595709059n/a 
2021-11-24gz.exeexe 465d3aac3ca4daa9ad4de04fcb999f358396efd7abceed9701c9c28c23c126dbVirustotal results 89.71%Hupigon