URLhaus Database

You are currently viewing the URLhaus database entry for http://188.212.158.75/5556.rar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3237976
URL: http://188.212.158.75/5556.rar
URL Status:flame Online (spreading malware for 1 year, 5 month, 26 days, 17 hours, 14 minutes)
Host: 188.212.158.75
Date added:2024-10-16 16:37:10 UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-16 16:38:12 UTC to nantawat[dot]pr{at}cloudforest[dot]co[dot]th)
Tags:exe Formbook link njRAT link rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-245556.rarexe 3f980de6bd0581609105f594ba932e5e54a9eb1afac81d7543a3a4da8aac9a6en/a Formbook
2025-06-235556.rarexe b09d66ba71975014fd70ae2ce38cebabe43cc14ec826fbd8ae4bb303f0d33380n/anjrat
2025-06-165556.rarexe b65ef9a5956b4dce670fb4499e77937faf24206ee9c2fd592d5402077008c2e8n/anjrat
2024-10-16n/aexe ef5c02c221b5cb992728758e29195115a8f5481cf9ca5072a0616f95d00a362cVirustotal results 84.00% njrat