URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.229/namec.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2028772
URL: http://2.58.149.229/namec.exe
URL Status:Offline
Host: 2.58.149.229
Date added:2022-02-04 16:31:16 UTC
Last online:2022-02-26 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: c_APT_ure
Abuse complaint sent (?): Yes (2022-02-04 16:32:31 UTC to abuse{at}serverion[dot]com)
Takedown time:21 days, 8 hours, 34 minutes Bad (down since 2022-02-26 01:07:13 UTC)
Tags:505757b55061ec62779307e5ef6beaa1 AgentTesla link fb0d531d6ad9e1d5c2ba5c16977d3c07 Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-16n/aexe f8d64de8061469f13cef1bffd0a1f45a5bea64f918acaf76026e04130185764cn/aFormbook
2022-02-11n/aexe 76d07b33364445e08dd5306a4e98d34edb6895a8269e9bb5aa9ef80e1cb83b2en/aFormbook
2022-02-10n/aexe 3d0defc77abb415c8854149e73e067b94bdb3fdc638fa7e104bcc4a325dc658an/aFormbook
2022-02-09n/aexe d79e66a74933a4b81b554372e47e6e5f7bb2d2b066de31289715bbd0de5b0718n/aFormbook
2022-02-08n/aexe 231a3fbd49c3daf40fef287f590ab7aa161ca51b09ecca28f5cdd92d4c9004abn/aFormbook
2022-02-07n/aexe 675fb254eabe2fda8786b7c7d6ce36d9cfb67e38f239815f71b9a4beef715e5bn/aFormbook
2022-02-07n/aexe 34fc8a270fda2856448cb455e3dca4d8210f5e83f25f1fa8339d8f428a449466n/aFormbook
2022-02-04n/aexe 06111314fa1419ceb56061648fdd8e9dcf8e167ed748cc41c722131d29905d1bVirustotal results 45.45% AgentTesla