URLhaus Database

You are currently viewing the URLhaus database entry for http://51.222.72.237/wp-includes/NPNGSFzuH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2205939
URL: http://51.222.72.237/wp-includes/NPNGSFzuH/
URL Status:Offline
Host: 51.222.72.237
Date added:2022-05-22 00:12:07 UTC
Last online:2022-12-28 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-22 00:13:06 UTC to abuse{at}ovh[dot]net)
Takedown time:7 months, 10 days, 5 hours, 13 minutes Bad (down since 2022-12-28 05:26:53 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-08n/ajs 7de7c4d02f7e36a20f763172178dc206f79331c55d4aab505837e6548a10bbdeVirustotal results 1.64% 
2022-12-08n/ajs cebfb62b37f9f1f0bb2d22fde84dbf3ecefedcd9e167e080e2544ac049ffaca1Virustotal results 1.79% 
2022-12-06n/ajs 71f3e4fbe97c1b61db8eb6b8130c6e0ca16fa92624e886d1f2bc9cfc4170218bVirustotal results 1.64% 
2022-12-02n/ajs e784b1a75528ca2c36e0d91d7b74e50bcbfdd374a5248f3d1ac667366b9c393eVirustotal results 1.64% 
2022-12-02n/ajs 4ff2bab4e31727f87697ddd8d30980a772cf4c01fd8573d0cc6beed0e2d8858dVirustotal results 1.64% 
2022-12-01n/ajs e6862b1f54c77529d67cf3cfa39c15239f9ad26ff402446796bfe4596a63001en/a 
2022-11-17n/ajs 0ee679884ef870cff17e2bc56c7e9ffe298e2328655ea28a7a127b46a18345d5Virustotal results 1.67% 
2022-05-221CbJBMMK61L.dlldll e1edcef9c64d771580c49994d7cbe06e4bb7948c3228f70ab27d83a9590f97afn/aHeodo