URLhaus Database

You are currently viewing the URLhaus database entry for http://194.50.50.249:45882/.i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:240718
URL: http://194.50.50.249:45882/.i
URL Status:Offline
Host: 194.50.50.249
Date added:2019-10-07 09:49:05 UTC
Last online:2020-02-24 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Petras_Simeon
Abuse complaint sent (?): Yes (2019-10-07 09:50:16 UTC to abuse{at}ip[dot]ro)
Takedown time:4 months, 20 days, 1 hours, 18 minutes Bad (down since 2020-02-24 11:09:09 UTC)
Tags:hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-13n/aelf 666830b93d483ab0d050c29c25e6b9596f105f919de7fc68a9bd6861e58e4f61Virustotal results 10.71% 
2020-01-20n/aelf c0cf6fcb0a3e3f0faa0c5bf491d470e5ce9f3e8127d4d2dfdd1b41259b8fbe04Virustotal results 33.33% 
2020-01-13n/aelf 780a93f74728e1cf2ee731da00997ea65f07742f1f30acc8762f58d0c5d57a67n/a 
2020-01-10n/aelf d94e0fe6fbd38c87dd4c6e9683dfe86941ff0834dbee7e2e6f0a67f4a999a020Virustotal results 29.31% 
2020-01-09n/aelf a684aa905a381608b339aa7a591ee95683ddaa603458c0c9a306b10a7e56a5e6Virustotal results 34.48% 
2020-01-09n/aelf 92c4026e8b2cc22c2acb8e8467bf63b9485bda367302d4c1e9a38a50d61c30adVirustotal results 25.00% 
2020-01-05n/aelf 1b7e2932997ac730ba745ed4bf9336581b0e28ccd31d5eeda1d9de1af45e5670Virustotal results 23.73% 
2019-12-27n/aelf 0bedda0199c336b09fe58ab9deb2691cae39ac5a98a41384021f7cb99359ab4aVirustotal results 25.86% 
2019-12-22n/aelf 404d195d5e3536933413f19e53307a14b099ba7872f9b6a4794dc09795570f03Virustotal results 39.66% 
2019-10-08n/aelf 74793f8699e6e1be5953ce7a15b03e07fb8701bb107eb941cdd30b3c41c5aaa3n/a 
2019-10-07n/aelf 020f1fa6072108c79ed6f553f4f8b08e157bf17f9c260a76353300230fed09f0Virustotal results 59.65%Hajime