URLhaus Database

You are currently viewing the URLhaus database entry for http://222.211.72.29:35641/bj.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1818852
URL: http://222.211.72.29:35641/bj.exe
URL Status:Offline
Host: 222.211.72.29
Date added:2021-11-26 05:11:07 UTC
Last online:2021-12-28 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-26 05:12:05 UTC to anti-spam{at}ns[dot]chinanet[dot]cn[dot]net)
Takedown time:1 month, 2 days, 4 hours, 35 minutes Bad (down since 2021-12-28 09:47:21 UTC)
Tags:exe Gh0stRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-01bj.exeexe a3259b3f139fe1e01e5918001a68101f80b378adf18a4e92ae72baba21f79505n/a 
2021-12-01bj.exeexe 3932aa428e2b3ba829733ff447943f37dd4bc00e60a1e217432e9f960b0f5b11Virustotal results 13.64% 
2021-11-26bj.exeexe 01b6902ab0179123e76d72184f38c96d3afc8fcef9aa5206920d228e8e9691a8Virustotal results 79.41%Gh0stRAT