URLhaus Database

You are currently viewing the URLhaus database entry for http://46.29.235.52/vnf12.exe#d12 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3158723
URL: http://46.29.235.52/vnf12.exe#d12
URL Status:Offline
Host: 46.29.235.52
Date added:2024-09-05 22:53:05 UTC
Last online:2024-09-17 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-05 22:54:07 UTC to abuse{at}gir[dot]network,abuse{at}globconnex[dot]com)
Takedown time:11 days, 8 hours, 44 minutes Bad (down since 2024-09-17 07:38:38 UTC)
Tags:dropped-by-PrivateLoader exe Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-06n/aexe 7f69b755604b2ba054290d816326a1f8f6ae1a10c460f1a94da936d017ebaac7Virustotal results 33.78% Vidar
2024-09-05n/aexe 1e1b2206be44e0cb6902bbc67c6435115f04ca308754e541f34fad64b20be6ebVirustotal results 37.33% 
2024-09-05n/aexe 600ff36d2f657156d0feb6698f1fc2c3abb42264ca77b9b911d1170972fbfdben/aVidar