URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.2/puty.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2215898
URL: http://2.58.149.2/puty.exe
URL Status:Offline
Host: 2.58.149.2
Date added:2022-05-28 21:04:03 UTC
Last online:2022-06-15 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-28 21:05:07 UTC to abuse{at}serverion[dot]com)
Takedown time:17 days, 10 hours, 3 minutes Bad (down since 2022-06-15 07:08:58 UTC)
Tags:32 AgentTesla link AveMariaRAT link exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-15n/aexe b47228784086e39923d8ee4ac620e0c5497ffc2af8dc1a8cffa0fe0a47d2b613Virustotal results 36.76%AgentTesla
2022-06-01n/aexe d364bb32fc468a1b11efd8a4434ed7c300a3232f699ebc11fc4d2050e6104df7Virustotal results 46.38% NanoCore
2022-05-29n/aexe 26c71cb3812cef12304be958380ac2b257469b375930533a8c44354c8510e519n/aAveMariaRAT
2022-05-28n/aexe f4248f09778780307d68ed068ed5cdcea48ea1c13555bd7bb05ce7f641017833Virustotal results 28.99%NanoCore