URLhaus Database

You are currently viewing the URLhaus database entry for http://61.172.11.252:12244/.i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:141302
URL: http://61.172.11.252:12244/.i
URL Status:Offline
Host: 61.172.11.252
Date added:2019-02-21 04:18:05 UTC
Last online:2019-02-23 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-02-21 04:20:06 UTC to anti-spam{at}ns[dot]chinanet[dot]cn[dot]net)
Takedown time:2 days, 7 hours, 40 minutes Poor (down since 2019-02-23 12:00:19 UTC)
Tags:elf hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-23n/aelf dfa2dc1a783190ad08e105afe2eacbb47e831be907d82a9aa96aef59f39989dcn/a 
2019-02-22n/aelf 63d9b625ee8364a4c0822650ca13f598677ec56c824953dc61fa094b425cca92n/a 
2019-02-22n/aelf 80cd700ac80f6c1ee8577aee27a3b889d847460e27555308451b8579b8914ae9n/a 
2019-02-22n/aelf ea5abe0e20adb34a78ad1371a5780a3c05540c9ef06faa8fb733cc2f0e0a6ddan/a 
2019-02-21n/aelf d8c51a2f4efe8e92401d763477bfac10774c561c631eeecca306a1eb1f5da6c3n/a 
2019-02-21n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 54.72%Hajime