URLhaus Database

You are currently viewing the URLhaus database entry for http://118.107.0.254:2002/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3777258
URL: http://118.107.0.254:2002/02.08.2022.exe
URL Status:Offline
Host: 118.107.0.254
Date added:2026-02-13 16:44:08 UTC
Last online:2026-02-28 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-02-13 16:45:29 UTC to cs[dot]mail{at}ctgserver[dot]com)
Takedown time:15 days, 3 hours, 48 minutes Bad (down since 2026-02-28 20:34:00 UTC)
Tags:censys CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-2802.08.2022.exeunknown 0c7ee46f962a98d3217895e65b18a90ad4583faeb57b23fa50626c97a6c2961bn/a 
2026-02-2702.08.2022.exeunknown 86f80657016cdbbf1424f1903ba27c0cb6f9aac80de008ab418806c2430baec5n/a 
2026-02-2402.08.2022.exeunknown 9ebcca59d79dae00ec8cb9c398f380f9abff5e7c14a8d942c67388efca350564n/a 
2026-02-2002.08.2022.exeunknown 356ffb39b4bf04827014a121c91ed0ff6cb425064eee1ccc385c3344ac727bden/a 
2026-02-1402.08.2022.exeunknown 5e7202a4803ebdab669e0a5343bc61db5d12397565743c2c53ab56290c8a61a5n/a 
2026-02-1302.08.2022.exeunknown 5341f6e8a26c4d744e93da467c1e85b0be53be682c24ca3c89d731f6391d7163n/a