URLhaus Database

You are currently viewing the URLhaus database entry for https://123.58.64.57:34567/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3774676
URL: https://123.58.64.57:34567/02.08.2022.exe
URL Status:flame Online (spreading malware for 3 months, 18 days, 2 hours, 16 minutes)
Host: 123.58.64.57
Date added:2026-02-08 17:41:25 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-02-08 17:43:00 UTC to support{at}cnispgroup[dot]com)
Tags:censys CobaltStrike link shellcode

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-0802.08.2022.exeunknown 671d7880293ddf107635ae4f208ea0ef639d9f8e5292e310f58aa377762eadcan/a 
2026-04-2402.08.2022.exeunknown 09acdb74790372d757e3ed998a50893d18641fd0b3fe9acacc33a4f2123bc7bdn/a 
2026-04-2302.08.2022.exeunknown 9823505882bf8f5b7c4fde5747bdc3e46651451da379f8091ec12e9ce22fa79dn/a 
2026-04-0202.08.2022.exeunknown 8c30221ee1b0f8c5d0d8d057b5bc8452519aefb814cb20281cfd609ef3416b81n/a 
2026-04-0202.08.2022.exeunknown 7c5edf78fa6e5c96284a6b166d52665041756521d199d9e3e98f3c76a5e02adfn/a 
2026-03-3102.08.2022.exeunknown 6ce8a757d8b2482d43e04702d544428af1426849c1735c5813f3c063574d3845n/a 
2026-02-0802.08.2022.exeunknown 4c04b5890f9c266559d0a9cfe38f7c5f7a7a04385d17bb476b76104ed2a6d3b2n/a