URLhaus Database

You are currently viewing the URLhaus database entry for http://1.94.97.137:8000/cobalt_strike_4.7_www.ddosi.org/cobaltstrike-client.jar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2748582
URL: http://1.94.97.137:8000/cobalt_strike_4.7_www.ddosi.org/cobaltstrike-client.jar
URL Status:Offline
Host: 1.94.97.137
Date added:2024-01-13 05:58:14 UTC
Last online:2024-01-25 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: adm1n_usa32
Abuse complaint sent (?): Yes (2024-01-14 04:12:05 UTC to ipas{at}cnnic[dot]cn)
Takedown time:11 days, 3 hours, 4 minutes Bad (down since 2024-01-25 07:16:38 UTC)
Tags:CobaltStrike link jar

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-01-25n/azip 513f84e1174150fb623d21d3489233eba6665e9f074e1a85033ffa23a0cb3913n/a 
2024-01-23n/azip 1bdd5e709ff102341e43a928b3d57796bc0fc9c395b9dc7540911b664ea8d7ban/a 
2024-01-23n/azip 4ea3dd52523ec8de26268f3381f4bdf3c433486e4e8de103c4b42b9c753ee773n/a 
2024-01-23n/azip ab65a18783b00c3b2627c45365706197a4ad25a70a65739665350f0bb3f7932fn/a 
2024-01-14n/azip d01571dfc95d39ebc3befdf691d2ce2183c84b82fc7d46904efe63c41222fc0fVirustotal results 70.97%CobaltStrike