URLhaus Database

You are currently viewing the URLhaus database entry for http://111.231.145.137:8888/supershell/compile/download/%D1%83%D1%81%D0%B5%D1%80%D0%BB%D0%BE%D0%BD%D0%B32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3086404
URL: http://111.231.145.137:8888/supershell/compile/download/%D1%83%D1%81%D0%B5%D1%80%D0%BB%D0%BE%D0%BD%D0%B32.exe
URL Status:Offline
Host: 111.231.145.137
Date added:2024-08-03 08:26:38 UTC
Last online:2025-07-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2024-08-03 08:27:18 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 year, 0 month, 2 days, 2 hours, 40 minutes Bad (down since 2025-07-31 11:07:45 UTC)
Tags:supershell supershell-c2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-09%D1%83%D1%81%D0%B5%D1%80%D0%BB%D0%BE%D0%BD%D0%B32.exeexe 55873d76fc2643ecc0022a71edb0060ff46b3f13c635e0e9a7c0a1df9e4aa1dcn/a 
2025-03-19n/aexe 2005d7df0bbab54864cba0b2e4bc86688d170180deb5189a8d9911261d776da7n/a 
2025-01-24n/aexe 7d120bdde12b78b075dafc287a4f074f7258ccf89e95bead8673fb1d3e071816n/a 
2024-10-06n/aexe 59e9db48e8888878d902e0ab9316f00575008999a11a49da1a5e3b2712249a9an/a 
2024-08-21n/aexe a1d3c5ab928c55fefeb41405c71a1f1e8236db2461445e86aa2f2677ae4c9a81n/a 
2024-08-10n/aexe c68ef9358b30b43e500e29a3db9460d2f1111ac8e2e9b8e2ee3f4b154f684a52n/a 
2024-08-03n/aexe eac4b5ccc69f0e43af59045cb2d382aaf8bbe1ffcd904c3613ff9c4cbe8e1cd0n/aSupershell