URLhaus Database

You are currently viewing the URLhaus database entry for http://47.98.177.117:8888/supershell/compile/download/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2942727
URL: http://47.98.177.117:8888/supershell/compile/download/1.exe
URL Status:flame Online (spreading malware for 1 year, 9 month, 5 days, 21 hours, 47 minutes)
Host: 47.98.177.117
Date added:2024-07-07 15:19:39 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-07-07 15:20:55 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Tags:exe supershell-c2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-071.exeexe 8f4f211b484df0c141a7277b557ff1c535f430a68f1438feaec6e4c36da6d5edn/a 
2025-05-121.exeexe c06349ded0f697bc1eeb641d6f9de069a62b3c17e325819a14580bf3cb675d3en/a 
2025-03-18n/aexe af16b00321680be28fb6440989c41a532d7a15a7765994ab71c28ea307c05151n/a 
2025-01-23n/aexe 8c77c888be9809297b897f729a040def1dfd792b087c34ad9d71f034372ac3dcn/a 
2024-10-04n/aexe 66890dc2f8932e67782e418fa22709001b1f3bb89e7310659e1f0ec2ad604a9cn/a 
2024-09-05n/aexe 6498fd665b3807d9574a4bd6204286fc969f50f04e9b327ce61497a4edf77d3fn/a 
2024-08-23n/aexe 0c3134e8f0f0de0dce1c9acd5df1eaaf232779e92591d3050d17e76d5e071fa5n/a 
2024-07-07n/aexe 9cf676141b7d305df5a9237c01e15138246392b0941657b55b3427776b7899d3Virustotal results 26.03%