URLhaus Database

You are currently viewing the URLhaus database entry for http://211.108.60.155/MpMgSvc.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2916093
URL: http://211.108.60.155/MpMgSvc.jpg
URL Status:Offline
Host: 211.108.60.155
Date added:2024-07-01 09:55:27 UTC
Last online:2025-04-18 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: Reedus0
Abuse complaint sent (?): Yes (2024-07-01 09:56:06 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:9 months, 20 days, 17 hours, 43 minutes Bad (down since 2025-04-18 03:39:43 UTC)
Tags:BlackMoon Gh0stRAT younglotus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-02n/aexe c751d97251cd67604c0256b779fabac87d4ed2d647ce0d830e2a1670cd3616c6Virustotal results 58.90% Gh0stRAT
2024-07-01n/aexe 284c6ee697899025ca021e7802721784f920be0818c668b2eb3031365902c4d5n/a 
2024-07-01n/aexe f2af31b74bfe1648b8c06ce5b3869e81ce8caafe4a265e007af4036af3448ae7Virustotal results 86.30% Blackmoon