URLhaus Database

You are currently viewing the URLhaus database entry for http://47.98.177.117:8888/supershell/compile/download/12.apk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2968679
URL: http://47.98.177.117:8888/supershell/compile/download/12.apk
URL Status:flame Online (spreading malware for 1 year, 8 month, 29 days, 20 hours, 8 minutes)
Host: 47.98.177.117
Date added:2024-07-13 16:58:36 UTC
Threat:Malware download Malware download
Reporter: RacWatchin8872
Abuse complaint sent (?): Yes (2024-07-13 16:59:23 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Tags:apk supershell-c2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-1012.apkelf 008aaa28447e3f4f2ea0e8f4cdc98bed89ecfc1f89142175a8e0996f23ad2139n/a
2025-06-2712.apkelf 69d1784a5f3473bc7ed2c367ac83f78632d7cb78a54db8605776bbfa0d407b92n/a
2025-05-0912.apkelf 5a36878411d5e847b4e7aefe785e3367a5e8e2f73a7d56180ff6daae8fb4de06n/a
2025-05-0912.apkelf 54baa433ebf239234e519ebc8512c7999e466610b0b6d3e51a3e5896f9ca7847n/a
2025-01-27n/aelf 3cb5d1cfa512dc9b396a33f8acbc3cdcceab6cb9f15a2ef5b1771808ffbc3251n/a
2024-08-19n/aelf 0d49c8b6c3c1de0a5f6553131950ed73489be818e4ab254f04352e9dd4483f5bn/a 
2024-07-13n/aelf db60e2265c30c73e41e429ff4d402c5575f2d5c1e4bc17db60e31a24a9ec721aVirustotal results 1.52%