URLhaus Database

You are currently viewing the URLhaus database entry for http://47.109.48.57/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3562747
URL: http://47.109.48.57/02.08.2022.exe
URL Status:flame Online (spreading malware for 8 months, 16 days, 8 hours, 29 minutes)
Host: 47.109.48.57
Date added:2025-06-16 21:36:34 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-06-17 05:19:11 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Tags:censys CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-1202.08.2022.exeunknown d2ebb66a038c520b9f49d489ad9ada2e6c0ed58836af578f1f090bc3faec0786n/a 
2025-09-0202.08.2022.exeunknown e45d4baf5c4163c45019fd345d60a86dbcb27180f062991ff2b63a2b03c63cc6n/a 
2025-06-2902.08.2022.exeunknown e1a976f0532e8fa9605f499e293cf34c4e5c142c77a81897d628432573111ab8Virustotal results 27.42% 
2025-06-1702.08.2022.exeunknown 3c6ec83eed3f96387e164ba7aa7c68def63bef6b78eee233d0893e7f8bf490f8Virustotal results 27.42%