URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as TORNADO.

Database Entry


Signature:TORNADO
Firstseen:2025-12-13 11:31:25 UTC
Lastseen:2025-12-16 06:19:19 UTC
Unique Payloads:2
URLs:2

Payload


The table below shows all payloads that have been identified as TORNADO.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-12-16 06:19:19c1abe0b35bbce86644dfb7a54934d8dfcf27e3d7f637f8394ae9b64b39222b6eExecutable exe5'628'416n/a
2025-12-13 11:31:25dff3831f6b85bd3309c4dbe0f23b92c3ad93a9104cfdde2632f13f3f9c206d11Executable exe2'358'816n/a

Number of entries displayed: 2 (max: 1'000)