URLhaus Database

You are currently viewing the URLhaus database entry for http://119.91.25.19:8888/WxWorkApis.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2869849
URL: http://119.91.25.19:8888/WxWorkApis.dll
URL Status:flame Online (spreading malware for 1 year, 7 month, 20 days, 19 hours, 44 minutes)
Host: 119.91.25.19
Date added:2024-05-31 06:26:20 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-05-31 06:27:09 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Tags:backdoor

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11WxWorkApis.dlldll 29cdda6298d07159835fd194ac8c4bb38264a03d4b857938d57e5b25843e6e3an/a 
2025-07-19WxWorkApis.dlldll 077c1e12c5e35d7d2ea23b0b0d5451973e7af0764b1fd3f56ea359f6b8294d35n/a 
2025-04-03WxWorkApis.dlldll 423318bdd2521f484e156d1856fbd4ea1b05ad4b0cc9d09c914899b9aba12581n/a 
2024-11-20n/adll 9b6792ab735d4b36ecd720a21360a6749536885bd523b8693738e5eb90230b74n/a 
2024-05-31n/adll 42bcd4c61e68a5dc2b7ce3b7cd2a61945ba3d8073380f46e47bb9cbdc295dc28Virustotal results 28.38%