URLhaus Database

You are currently viewing the URLhaus database entry for http://62.60.226.159/Loader.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3729467
URL: http://62.60.226.159/Loader.exe
URL Status:Offline
Host: 62.60.226.159
Date added:2025-12-08 20:16:13 UTC
Last online:2026-04-30 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-12-08 20:17:13 UTC to abuse{at}as214351[dot]com)
Takedown time:4 months, 22 days, 10 hours, 15 minutes Bad (down since 2026-04-30 06:33:06 UTC)
Tags:a3dacb clipbanker dropped-by-amadey Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-24Loader.exeexe f8e7c3df513d88989ccad1b2a17f88c7effff717e8038cf9a88e7fee7be7ef5cn/a Stealc
2026-04-03Loader.exeexe 2f77b32d357ee32396ed1724ed88c5c5f9fd8db8cedbd1b07a1bb1d58989862an/a
2026-03-21Loader.exeexe ef2e4709accbe3d62d8784596ab04e397fe815b6222c09a3fb002cee67f719bbn/a ClipBanker
2026-03-12Loader.exeexe 351f8344a4781ad55196f66fcac7703d39b0f772c6a73dc38fdf4ada903dfde6n/a ClipBanker
2026-03-06Loader.exeexe fdb2d5861e396b1d0d0da042bfac70529680cdbb10713df28763615ad602cbedn/a 
2026-02-25Loader.exeexe 670c2800abc04f1612d73f0df5f5040f6f348a55464dac69039e5ef1ecc79575n/a 
2025-12-25Loader.exeexe 1586e6f714547d9ec024c9aeff1df7024d37a867d543de418b0af65c530c6738n/a
2025-12-22Loader.exeexe be57810a4368072cd8fef14a58e56274aa340432efe4bdfa57453d56705bfc4dn/a 
2025-12-18Loader.exeexe 53950d2a91c37fb1783568119609e1ba58fa9860c23463c09b86da35816e8981n/a 
2025-12-08Loader.exeexe ae412742dee23f32a1e69750fc09fe69c460d61fd0db8141967ecd67276bcee5n/a