URLhaus Database

You are currently viewing the URLhaus database entry for http://110.41.14.58:8000/%E5%9B%BD%E5%BA%86%E5%BB%B6%E8%BF%9F%E6%94%BE%E5%81%87%E9%80%9A%E7%9F%A5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2908949
URL: http://110.41.14.58:8000/%E5%9B%BD%E5%BA%86%E5%BB%B6%E8%BF%9F%E6%94%BE%E5%81%87%E9%80%9A%E7%9F%A5.exe
URL Status:Offline
Host: 110.41.14.58
Date added:2024-06-27 07:59:06 UTC
Last online:2024-07-13 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: fbone3
Abuse complaint sent (?): Yes (2024-06-27 08:00:13 UTC to ipas{at}cnnic[dot]cn)
Takedown time:15 days, 23 hours, 43 minutes Bad (down since 2024-07-13 07:43:30 UTC)
Tags:CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-01n/aexe 4e137dda612129b09c80e1d56ef1c72a01e41c113f33455fe68cfc04b8bc1b8dn/aCobaltStrike
2024-06-27n/aexe 6419aa3ff941635038f6ed18b64b59c413076d33e59782154fa59c65936e3915Virustotal results 75.68% CobaltStrike