URLhaus Database

You are currently viewing the URLhaus database entry for https://62.60.226.185/tu3929.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3906179
URL: https://62.60.226.185/tu3929.exe
URL Status:flame Online (spreading malware for 2 days, 6 hours, 58 minutes)
Host: 62.60.226.185
Date added:2026-08-20 13:16:07 UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-08-20 13:17:21 UTC to abuse{at}as214351[dot]com)
Tags:Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-22tu3929.exeexe e2f09c867cb0194c3d7de3c01c9895a14c53d1dd7442a8965248b3ada1b7b945n/aVidar
2026-08-21tu3929.exeexe 3b39762bbe07ca79b3d8db0e96d5cda84aee772becc387f52abc5d395b4024ean/aVidar
2026-08-20tu3929.exeexe ad821edb933557752728e1c68d3feb55258c99bb2c544e7a189c580ffe1bb546n/aVidar
2026-08-20tu3929.exeexe b1ec921ab8b8c04be4f13b9ad814e8e3f2d6c046891c74211143330b5492dbd5n/a Vidar