URLhaus Database

You are currently viewing the URLhaus database entry for http://8.134.74.227/gg2.hta which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3594332
URL: http://8.134.74.227/gg2.hta
URL Status:Offline
Host: 8.134.74.227
Date added:2025-08-01 14:58:35 UTC
Last online:2025-10-24 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-01 15:08:09 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:2 months, 23 days, 20 hours, 29 minutes Bad (down since 2025-10-24 11:37:35 UTC)
Tags:geofenced ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-24gg2.htahta 48a1a559f2b229ea4b5ba68175663249ffc85f5ffc7d3ecf8fc4e270ffa513acn/a
2025-10-12gg2.htahta c3cef0d64c1f62713be5b27d586af79e9bb65d8ba78117c951c758d421aa1038n/a
2025-10-08gg2.htahta 1de2ba24e272c06abd291ce413b2f3d935285dc55463827549b22396f401aefdn/a
2025-10-02gg2.htahta 12e09180acdbd6e2620c333973c37aa66347503202015d47bbcf4f278d4461f7n/a
2025-09-01gg2.htahta 65e7379384f0debbb9dab01c7c3f9764d1f878b39ec3546ab273ca1d4730fafcn/a
2025-08-31gg2.htahta 11da62138e7f93ad21217e884246c2341e5ffc8faab0b5f6b02205ff08fc6122n/a
2025-08-28gg2.htahta 0e8c1bd6494bd82dc0f3ad1e21815f7348e1bfe412b7b0bcd22a58d523fd204bn/a
2025-08-11gg2.htahta 00be7f643a12ac2221c9ba8df4fb34b3701c336fa830d24fe906c55364ef7b35n/a
2025-08-02gg2.htahta 68b297d80aa383884c5b1c657a8f05864912f5d38023317a5a0b8caacb55fa68n/a
2025-08-01gg2.htahta cc0d485085cf6b766fd94f4dd4887b947de79aed10d4b2bc18f3fab393deadeaVirustotal results 47.54%