URLhaus Database

You are currently viewing the URLhaus database entry for http://62.60.226.159/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3721528
URL: http://62.60.226.159/1.exe
URL Status:flame Online (spreading malware for 2 months, 3 days, 9 hours, 25 minutes)
Host: 62.60.226.159
Date added:2025-11-30 13:56:06 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-11-30 13:57:14 UTC to abuse{at}as214351[dot]com)
Tags:c2-monitor-auto dropped-by-amadey Stealc SVCStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-061.exeexe a548b65783231dc2d4a936ac0cdde7ae373ac84e1142a7678bd045b9d129cc06n/a Stealc
2025-12-301.exeexe 53254632d9c8ea25e0a466503c597a160fcf8efa013e7236a6655e9d0a4faed2n/a SVCStealer
2025-12-251.exeexe e716fecd4ed32d90b1c707da5b419c65a7e1d89b4e416ee69765a3729c1e3293n/aSVCStealer
2025-12-131.exeexe 7e9d3236eb6c30eaba04f7480a3b00aa2d0c990e101d120c11325e6b4faacdf8n/aSVCStealer
2025-12-011.exeexe 4caf2a7831a78d5e22fee325aef6b7aa350b43226c7392fa086a2f5cd13c51f8Virustotal results 51.39%SVCStealer
2025-11-301.exeexe 207e0c77158970216870c9515d408d2437e4734b88bb6b2fe77326c99f1e0404Virustotal results 48.61%SVCStealer