URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.44/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/6eq5gvOfRvNmCi54.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3889916
URL: http://158.94.208.44/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/6eq5gvOfRvNmCi54.exe
URL Status:flame Online (spreading malware for 2 days, 7 hours, 23 minutes)
Host: 158.94.208.44
Date added:2026-07-22 00:11:18 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-07-22 00:12:18 UTC to abuse{at}omegatech[dot]sc)
Tags:6e7868436f4d3b49f375773379ba9022 dropped-by-remus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-236eq5gvOfRvNmCi54.exeexe 4b33ef08b2517ca180b3ecb2917c5196965cbcde84e3bb8a83b156ee55c4a622n/a
2026-07-236eq5gvOfRvNmCi54.exeexe 20c2d0ac02cf69f4288024801a0c90c3a43f79f1be43a7c3621548cf16b0de15n/a 
2026-07-236eq5gvOfRvNmCi54.exeexe 257b0a4ddddf3a50937301e9a4bbd8c5fc508b0890fc16682a3b9f1d412f76f5n/a 
2026-07-236eq5gvOfRvNmCi54.exeexe 2485d9a51fc370a064613f490bd16df1553e3edb4fc38cbede4023e046932a33n/a
2026-07-236eq5gvOfRvNmCi54.exeexe 371d61eb559b29638bdd41d9574704a5029b01d201461e3ae4c3fd05590fe2bbn/a
2026-07-226eq5gvOfRvNmCi54.exeexe 091b35d487c4172e888a0276244dc453332f2152f837b1500ded3591c7d9846an/a
2026-07-226eq5gvOfRvNmCi54.exeexe 21796e5def787676275be4ee84a07687f6f4ace6c009cbd394da24ec95b24dbdn/a
2026-07-226eq5gvOfRvNmCi54.exeexe 23494415bafe76ea0729d47f7bbd1fb0b91aa747b0c45296713b41c1b63c24a6n/a