URLhaus Database

You are currently viewing the URLhaus database entry for http://121.4.98.100/Server_se.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2354969
URL: http://121.4.98.100/Server_se.exe
URL Status:Offline
Host: 121.4.98.100
Date added:2022-10-10 07:25:08 UTC
Last online:2023-03-18 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-10 07:26:11 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:5 months, 8 days, 19 hours, 13 minutes Bad (down since 2023-03-18 02:39:18 UTC)
Tags:darkcomet link exe nitol link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-21Server_se.exeexe bbde5ccf7a6250935f1ed4d874bbd8bf1527accb8744554c54b0a687235a099bn/a
2023-02-11Server_se.exeexe e12d85aa606d45cdbb85982f5ea17d5c0b6f030dbbb30275ec0803f37c188a5bn/a DarkComet
2023-02-08Server_se.exeexe cdc95392f7aaf04457256258571c08966e093503028339eeeb586a3d1d2903e0Virustotal results 54.29%DarkComet
2023-02-07Server_se.exeexe 8fb5fd7d1966ce184b87ea565e3eb6e7c310f6b96424e1122dab6804a33e55fcn/a
2023-01-25Server_se.exeexe cdd11ebf519062185fee0ce1ca1d79a4c2b608937782e2d6f81d359b45f3f49an/a 
2023-01-07Server_se.exeexe 9af327b367b69a023c5269d7da2f73dbf7cb56580f6ac9a108c4bcb3a622842dn/a 
2022-10-10Server_se.exeexe bb10d1876255ac5c7beb971b9c3f748976eef78067690392f36e698939331ac1Virustotal results 76.39%Nitol