URLhaus Database

You are currently viewing the URLhaus database entry for http://60.22.23.50:9898/ykwsyyt/help/HDDrive1095_XinAnPlug3030_20230619_inno.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2787791
URL: http://60.22.23.50:9898/ykwsyyt/help/HDDrive1095_XinAnPlug3030_20230619_inno.exe
URL Status:flame Online (spreading malware for 2 years, 2 months, 18 days, 3 hours, 16 minutes)
Host: 60.22.23.50
Date added:2024-03-20 15:34:37 UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-12-20 07:41:04 UTC to zhaoyz3{at}chinaunicom[dot]cn)
Tags:32 exe Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-03n/aexe eed9fd0d3dd6e92a7fedc000ae3858ed21c01743bc77e6a4d48d5fbe78810242n/a Socks5Systemz
2025-01-01n/aexe 6a5d951c6012075bd275abb053e496cd48f3d94a5c39f06b71311ebc6004c238n/a Socks5Systemz
2024-10-16n/aexe 075df7f905f4ce6037daac36a3f08bf34c812ea6204bdc25a40374b7656bcaaen/a Socks5Systemz
2024-03-20n/aexe 7e1d1070aad3420a51dd4fd4474bdc04a34e68699a31ad28398916dc616b3f96Virustotal results 15.49%