URLhaus Database

You are currently viewing the URLhaus database entry for http://111.231.145.137:8888/supershell/compile/download/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2942717
URL: http://111.231.145.137:8888/supershell/compile/download/1.exe
URL Status:Offline
Host: 111.231.145.137
Date added:2024-07-07 15:19:28 UTC
Last online:2025-07-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-07-07 15:20:49 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 year, 0 month, 28 days, 19 hours, 48 minutes Bad (down since 2025-07-31 11:09:15 UTC)
Tags:exe supershell-c2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-081.exeelf 483ede279e1ad4fec2f611b9cb421c91fa235680498eb7fd879a06d03d9e782bn/a
2025-02-26n/aelf 3b11ddc73cedfc7eb3a73904d1f40ef1670a2060385e9c01c5a0f162ce8a70e3n/a
2025-01-26n/aelf bbbb08d484212faa431d3b99862425f8a2fb0fbfdb706e2c9cb0f8f36fe91e69n/a
2024-09-27n/aelf a552891efed2d7918e7ecc002f5bdc227a0402d4b0d33a7c6bfdef919a51849en/a 
2024-08-26n/aelf c6ec609f8e5836cc9ffcc95cd0ad5f78361687784505f6d83ef9c6f9dbba40b6n/a 
2024-08-23n/aelf 10dcc687303ee092585f924e8021b1c51db2842dd23d01376b1462a97ae60bf6n/a 
2024-08-17n/aelf 901f9f0fccc0c5ebd2f1f889dbc11f45ed96cb4842a926a868d3b189f4a95739n/a 
2024-08-11n/aelf a83417878f7801f6186ed9c22528c644efe910ca4507c910e714f6af61341f25n/a 
2024-07-07n/aelf a452423c5dd951e6a1b4e2a1fcc760a5c9c73932a543f3c33b23702cfe62f3ebVirustotal results 1.52%