URLhaus Database

You are currently viewing the URLhaus database entry for http://167.235.240.0/ntredirect.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2595127
URL: http://167.235.240.0/ntredirect.dll
URL Status:Offline
Host: 167.235.240.0
Date added:2023-04-02 22:55:04 UTC
Last online:2023-04-11 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2023-04-02 23:07:05 UTC to abuse{at}hetzner[dot]com)
Takedown time:8 days, 13 hours, 17 minutes Bad (down since 2023-04-11 12:24:46 UTC)
Tags:dropped-by-amadey LaplasClipper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-09n/adll c314bec57a53acfd55c1aa6c4c4bb49784e2c944c8e8d700c08e63f1ad80e659n/a 
2023-04-07n/adll f0475c7dc0aeeb162c86b54d19a83a3c1065c2944d0a7d810868c8b96bd8ce24n/a LaplasClipper
2023-04-02n/adll 8b9b5bd8b2621c1c2fd22bd488ec94882c93539b51f14ac29e64951c0b84cee8n/aLaplasClipper