URLhaus Database

You are currently viewing the URLhaus database entry for http://216.83.57.208:7979/DHL27.124.10.236/chrome_elf.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1106100
URL: http://216.83.57.208:7979/DHL27.124.10.236/chrome_elf.dll
URL Status:Offline
Host: 216.83.57.208
Date added:2021-04-11 01:25:06 UTC
Last online:2021-04-13 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-04-11 01:26:03 UTC to abuse{at}ethr[dot]net)
Takedown time:2 days, 5 hours, 3 minutes Poor (down since 2021-04-13 06:29:10 UTC)
Tags:exe nitol link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-12chrome_elf.dlldll 670cbec5ce5da74626a778fcff3bc15b62fc0608750eaa512c5ac8ba4c5d7a87n/aNitol
2021-04-11chrome_elf.dlldll ff5e1e92b5ae4bffa787cb69dd1689d27669497ed46ff0a49d90beb02c4596d3n/a Nitol
2021-04-11chrome_elf.dlldll 048e07e3447c113aaae05330089da2aab121cbd9ca29f021e2c4d1c93307778cn/aNitol
2021-04-11chrome_elf.dlldll b1c12faf9d61cc34d9d34a20fe2c199a4bb7ed0b1437aae2f13f2f556a23b2e2Virustotal results 27.54% Nitol