URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.211.222/final/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3790644
URL: http://158.94.211.222/final/random.exe
URL Status:flame Online (spreading malware for 1 day, 4 hours, 0 minutes)
Host: 158.94.211.222
Date added:2026-03-06 12:52:09 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-06 12:53:13 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-amadey fbf543 NirCmd

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-07random.exeexe fa04c4f8e49bbc23001b746632c27ce94e1b176141455cc95831f5e6d83dd131n/a 
2026-03-07random.exeexe d32a7418dbab5c43ca9be893ccdf4b7edae9276dc8bb53bbb759b78d65d32437n/a 
2026-03-07random.exeexe 973f2013840e54bd9b12e31938b0592cad17c23425304fecd1ce072aad4d45d2n/a 
2026-03-06random.exeexe cb1da42e8e4283d5639f54e319dcd76480d9a507206e5b328aa8a6795c6404c3n/a 
2026-03-06random.exeexe 94bd0cc1f5b87d454af3f6be2ea6f6531795fb6b6d1078136f6701121715c25fn/a 
2026-03-06random.exeexe 0d6f9701bbe0142a18e081bdd354895d9e3d678bbacd0a84c4080ea3eaeed5ebn/aNirCmd