URLhaus Database

You are currently viewing the URLhaus database entry for http://85.99.241.251:52424/.i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:228184
URL: http://85.99.241.251:52424/.i
URL Status:Offline
Host: 85.99.241.251
Date added:2019-08-31 03:19:06 UTC
Last online:2019-10-03 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-08-31 03:20:08 UTC to abuse{at}ttnet[dot]com[dot]tr)
Takedown time:1 month, 3 days, 7 hours, 20 minutes Bad (down since 2019-10-03 10:40:46 UTC)
Tags:elf hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-02n/aelf 88a707b0a03dc187d1b4b01e21397c9285ecdcf81e257b841c75cc0314594784Virustotal results 1.69% 
2019-09-29n/aelf 46f017311939733df19371fde5e18d8bae8bdb9c5454a0e2029b2f6e6aaa9bcfVirustotal results 3.85% 
2019-09-27n/aelf 395c7b3c97606a5f12653404bc39fbcfa088def84c22e84f7f72071dff509061Virustotal results 1.89% 
2019-09-14n/aelf eae5127c807219cd354bfb5d379eed0b0bacc778c25d931dce6f2ebdda711902Virustotal results 1.85% 
2019-09-13n/aelf d455e1d4db5f07bdb7627b1bed4bdd4eb108da47ed3314483cd482051d27532an/a 
2019-09-11n/aelf 635b6c314a8270a030718113fd709fa67489fd4293db028615e9f821cfedcb4aVirustotal results 1.75% 
2019-09-10n/aelf a70de627b2fbcde0e486c0fb3e5f77bddb0b4f99e2ba549ae069203d28e7ffb8n/a 
2019-09-08n/aelf 1cdb613a976d451a6421eb99a1a62a1ca8759c4856de02ab404d8c8ed4abf81aVirustotal results 3.39% 
2019-09-04n/aelf fc81415c1b5d6fa48fe0e36f7864a6da96e91788d408e55b0c50ac078e8082c2Virustotal results 1.72% 
2019-08-31n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 63.16%Hajime