URLhaus Database

You are currently viewing the URLhaus database entry for http://192.162.199.246/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/9z7BGnRGpgs8cZv7.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3894881
URL: http://192.162.199.246/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/9z7BGnRGpgs8cZv7.exe
URL Status:flame Online (spreading malware for 1 day, 12 hours, 23 minutes)
Host: 192.162.199.246
Date added:2026-08-01 01:32:08 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-08-01 01:33:14 UTC to abuse{at}as214351[dot]com)
Tags:42d208560b5e968930dcedab3c2bf57b dropped-by-remus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-029z7BGnRGpgs8cZv7.exeexe a495cb6ea1fce0b4a006562dc2e8d5db918acbf711192e10941fea612f792c20n/a
2026-08-029z7BGnRGpgs8cZv7.exeexe 25848334ac892d73fed07a04fca9b5ed55cc590fcf4a59c34b023fa35b1dfd00n/a
2026-08-029z7BGnRGpgs8cZv7.exeexe c1fd57d1c2fa32e530ce16b95a306e98cd098e44e4599e9daa5d700d0a437814n/a
2026-08-019z7BGnRGpgs8cZv7.exeexe d52432ed7d8f19f60c23df99972160bdaec8beb70123e8f59213871f337dc847n/a 
2026-08-019z7BGnRGpgs8cZv7.exeexe edb9bdb68ef0f04c030300753b606d2a2cac2a7411554726d824ab20f2e53f2fn/a
2026-08-019z7BGnRGpgs8cZv7.exeexe 392a891929839c17887143fe1125f845763335821a61b83cf6a2a291d79b1885n/a
2026-08-019z7BGnRGpgs8cZv7.exeexe 6e67cde5f83e4a64ba7a626f46240979a840163e1595b7219ee850fac6826444n/a