URLhaus Database

You are currently viewing the URLhaus database entry for http://62.60.226.185/s0907.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3884702
URL: http://62.60.226.185/s0907.exe
URL Status:flame Online (spreading malware for 1 month, 0 days, 21 hours, 0 minutes)
Host: 62.60.226.185
Date added:2026-07-11 03:59:13 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-07-11 04:00:24 UTC to abuse{at}as214351[dot]com)
Tags:d52f85 dropped-by-amadey njRAT link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-03s0907.exeexe e2affa0d6d98ca6cd8dbb05f8db955a71127b37c631a9cea4c967bdc992c93e6n/a njrat
2026-08-02s0907.exeexe ac712a69261cb774982a217a3a45e68fe7e9fae39b3d5c2ee47e9283e57f0308n/a Vidar
2026-07-30s0907.exeexe 1590f5bc877168396a099a8726b2922c2f5fc4116c047719fca6a315ca33ba2an/a 
2026-07-28s0907.exeexe 3fbf80ac2add3ca54ef3f297ea818fe30991f5fe3d00f8bb450efb109ac8e8e2n/a 
2026-07-26s0907.exeexe 8b9ddcc6eca22ca038064e9571a9138dcea575d47cc60c64943e3f0c323b51b7n/a njrat
2026-07-19s0907.exeexe a48aa8c98fe8513870465f743e2f696a8c179b22496d8d99208e950f54743453n/a Vidar
2026-07-15s0907.exeexe e74456a7f7a68b46a907f8ed737aeac6b90cdf660affd32136152a94a47400b6n/a Vidar
2026-07-14s0907.exeexe b99c08e0d8c2191cd1c01bd30102b6e0659630c7c3d6183f7219d6deb5e5d209n/a Vidar
2026-07-13s0907.exeexe 6e42c22a3fc0f378992af1bab53101e2a755593cfd9f98429ea64563761854c3n/aVidar
2026-07-12s0907.exeexe c64dbd499f07110c2dea19c95f2515553c59dbc0ee89a0a175ba8509a32f942fn/a Vidar
2026-07-11s0907.exeexe 004ef0c7343d95409b3d44036052ed9eef38ad153311313c53260ed6adb47819n/aVidar