URLhaus Database

You are currently viewing the URLhaus database entry for http://107.175.64.210/zel/zel.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:269339
URL: http://107.175.64.210/zel/zel.exe
URL Status:Offline
Host: 107.175.64.210
Date added:2019-12-16 05:48:37 UTC
Last online:2020-01-09 19:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-12-16 05:50:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:24 days, 13 hours, 15 minutes Bad (down since 2020-01-09 19:06:02 UTC)
Tags:Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-18n/aexe 32d52a35ddf646d3e5b8225d32b9d47ee5469e0e02920d2d338c6510a04c142cVirustotal results 13.89% 
2019-12-16n/aexe 4560999f57f53700d8626372b0c8b98d9974cb443328c150b5cd7cbf4b346259Virustotal results 63.89% TrickBot