URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.202.49/elin.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:243614
URL: http://198.23.202.49/elin.exe
URL Status:Offline
Host: 198.23.202.49
Date added:2019-10-11 07:22:32 UTC
Last online:2019-11-08 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2019-10-11 07:24:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:28 days, 16 hours, 23 minutes Bad (down since 2019-11-08 23:47:09 UTC)
Tags:Nemty RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-20n/aexe 379f030e2b2ecadaa9e549e4d35d0999ded8b6c6f70fbfe055a0ed36dd6a6560n/a 
2019-10-20n/aexe 946dd8b5ea4fcdcb5dd093c1a8ec11f85db29e89652a9c4424554b861601c550n/a RaccoonStealer
2019-10-18n/aexe 0db61319b408a6771057b6a07037e0fb73ee8f247ca7b77098e59c1e0a60c294n/a RaccoonStealer
2019-10-18n/aexe 34dec8d8519b34160709d9203c4cd073a84988087996c073c8c51ad526405837n/a 
2019-10-17n/aexe 9d9b4c7194d4b844716396432a204671335bfebeb659427d5393b8d7110a2358Virustotal results 11.59% RaccoonStealer
2019-10-17n/aexe 6621e13aec327284f8158ef4198072fdeab69a509f3c07697b93a0439ba4bda3Virustotal results 8.45% 
2019-10-16n/aexe 9ce8ad9307f556e5335ee5f6d8739882c9320f7da90646038bbf483a5f31245fn/a 
2019-10-11n/aexe 8a8d651e009b2fae2d81147fbd9d95e843524beea2cfd0d39e9410255473d65eVirustotal results 18.57% Ransomware.Nemty