URLhaus Database

You are currently viewing the URLhaus database entry for http://62.60.226.185/tu3929.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3881810
URL: http://62.60.226.185/tu3929.exe
URL Status:flame Online (spreading malware for 23 days, 14 hours, 38 minutes)
Host: 62.60.226.185
Date added:2026-07-07 05:11:07 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-07-07 05:12:22 UTC to abuse{at}as214351[dot]com)
Tags:ArkeiStealer link c2-monitor-auto dropped-by-amadey njRAT link QuasarRAT link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-30tu3929.exeexe ec0078d806fcb7b0ef538a51ae03217888ce1bd3e96a73beceecc2c12675d77dn/aVidar
2026-07-26tu3929.exeexe 93957b5a9a08759bba54d3019b494896b02a5e444d7560a8b4dd10cf48e12fc9n/a 
2026-07-18tu3929.exeexe 89de93e69e898d5da92c572f472fc8d0b3b1162eb8d98d4790d2fd6ff849de5bn/a njrat
2026-07-16tu3929.exeexe 41139bdc7515c44f69162b1e5bf31be74636b4d8ce9bb2b5e8fa95cdd2919172n/a njrat
2026-07-15tu3929.exeexe bc4357dd9ee475e1c51d3bd716560f73568345523e91499dbd0a7d47d72f1a91n/a njrat
2026-07-13tu3929.exeexe 8aa30391aef3ffd2d5cdd93e76aa66a8ad5075adc22dd235882cf206b28c7f1fn/a Vidar
2026-07-12tu3929.exeexe a080bcab936bdde24f5b3010b4fdc6f8c32ecc4597dae3ed39cde2ea778cea21n/a Vidar
2026-07-11tu3929.exeexe 9e6539cb6fbfde0adb24de9813f7042d9713c952602c429238c06bbcebaf1dc5n/a QuasarRAT
2026-07-09tu3929.exeexe f51361ec07e2cc4833c58d706b6da8d4d4982ce8dd60ac89a78ca56c9e553680n/aArkeiStealer
2026-07-07tu3929.exeexe 720a3c7352a4ebaa95565e234fec74865a2dbe4e90e5e9cb308c8575e21f6565n/aVidar