URLhaus Database

You are currently viewing the URLhaus database entry for http://200.29.120.130:8002/tftp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3112426
URL: http://200.29.120.130:8002/tftp
URL Status:flame Online (spreading malware for 1 year, 3 month, 19 days, 11 hours, 45 minutes)
Host: 200.29.120.130
Date added:2024-08-17 14:01:11 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-08-17 14:02:21 UTC to lacnic[dot]emcali{at}emcali[dot]net[dot]co)
Tags:elf tftp

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-13n/aelf 3b64710b7ad8088bee054ecdc4216d051e9d0c7b3ad85849ea7f8d1abd005b2bVirustotal results 40.62%
2025-06-22n/aelf a0d4456c848f2f8a97441aad14e0fa1fc1a5125cca94743c416eb288ee3e7b4dVirustotal results 45.31%
2025-04-09n/aelf 0e771450ede22c9001e33926c6e6ba12b90ebb6f624fdd9d24c7b6de224895e2Virustotal results 33.90%
2025-02-22n/aelf 329ba74dc0bef00974d474d15b3d782a6de33e2ce67f78c7db6a296ad6e6c0e3Virustotal results 28.57% 
2025-01-27n/aelf b9e179d709b388e0794858e9940f6546a7cefb9f4865e6e3860ae4403baaaea7n/a
2025-01-17n/aelf 25c2e9bd91f68684e1e815e949b1108b3568e6885c788496b43f8b3dc5361df5Virustotal results 30.16% 
2025-01-15n/aelf d7cf856594765c67bb13dae673a1a2f2122f7b24555b76a62216a20a3237bf4cVirustotal results 18.97% 
2025-01-11n/aelf fb86b1ae70f7b067b400ad62b93e2bd2817d554ce22f2ca4c30535dcf2fd02abVirustotal results 25.81% 
2024-12-22n/aelf c5590232becfc7b5ef5c6b95abeb894e7f870d2175d31aaf9bf1cae4289552c1Virustotal results 23.44% 
2024-12-01n/aelf ee0d9c4f826faa615c38634aaeee5d861fe5965396fe85d2c7de45c11a471fa3n/a 
2024-10-10n/aelf 145528056ff380c26d5aeff1dd4949e6c5690922d47e11861586369d35f7d598Virustotal results 22.73% 
2024-10-10n/aelf 23dc91f87469f5b7536fa073ab28bbb61c0234261d48f6dbbc664e81df1d94ceVirustotal results 23.08% 
2024-10-07n/aelf 9590e45c8752e47194201003565309b4b2023d340a3800ac15808b4141e18becVirustotal results 21.54% 
2024-10-05n/aelf 14d98bed983d31163462f604ee2cdd6be8a25d1eed8105a9062bba391997405aVirustotal results 24.62% 
2024-09-09n/aelf df12b303824b9bcefb1ce78d1c30e6194a8ac870550957f9e45425122da5f99bVirustotal results 14.29% 
2024-08-21n/aelf 321490c64d66511f750c3977ab2429d52806fbb30c7c160398b8f37bf3d621eeVirustotal results 22.73% 
2024-08-18n/aelf 7b0ba2db25a9cd331cd5ac53d49580034f14219b719a8ae19647e384767b7574Virustotal results 21.21% 
2024-08-18n/aelf 829f76e09c6e3a92735fd324c0295e27cab04b8d4671d2eaa79c4579fe6b95c0Virustotal results 23.08% 
2024-08-17n/aelf 9b66676da9413803e42cb2efda1bb76084cdf89d40f503a6716f4eb719ac972fVirustotal results 29.85%