URLhaus Database

You are currently viewing the URLhaus database entry for http://45.8.146.139/fhfty/NH1-X8NL7CO4_YNJ-MEFY7BW9QYIJW1I/-f which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2271818
URL: http://45.8.146.139/fhfty/NH1-X8NL7CO4_YNJ-MEFY7BW9QYIJW1I/-f
URL Status:Offline
Host: 45.8.146.139
Date added:2022-08-11 15:49:13 UTC
Last online:2022-08-11 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-11 15:50:09 UTC to abuse{at}stark-industries[dot]solutions)
Takedown time:2 hours, 2 minutes Good (down since 2022-08-11 17:52:44 UTC)
Tags:IcedID link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-11loader_p3_dll_64_n3_crypt_x64_asm_clone_n105.dlldll f825f453f9f95c086ae9621e9058562f0c4000d14dba9b2dd14f1a4253d92842n/a IcedID
2022-08-11loader_p3_dll_64_n5_crypt_x64_asm_clone_n121.dlldll adcf3460a791678dfe2dd32200550b2ad2bccd98d79c62ffc5a8935c2f81a54fn/a IcedID
2022-08-11loader_p3_dll_64_n3_crypt_x64_asm_clone_n28.dlldll 4359d51994e31c16b89f61e9333773efe25f9f4001674a9670ebabcf425b9e00n/a IcedID