URLhaus Database

You are currently viewing the URLhaus database entry for http://211.204.100.20:1234/IATInfect2008_64.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3335147
URL: http://211.204.100.20:1234/IATInfect2008_64.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 26 days, 4 hours, 41 minutes)
Host: 211.204.100.20
Date added:2024-12-07 14:38:19 UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-07 14:39:33 UTC to irt{at}nic[dot]or[dot]kr)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-11IATInfect2008_64.exeexe 5070eec59e1db1b0e3bd64b8a8f25a5d5b60002bad26a0d99996f7635255132dn/a 
2026-01-18IATInfect2008_64.exeexe 6fca587cb8e4a96584cdd0eb541a717026c7674523781b93f414d1891267e842n/a 
2026-01-17IATInfect2008_64.exeexe 3e0fd3c473e64a55f14a765bad217359d0a05aac1ca4d95d108b134524b6f98fn/a 
2026-01-17IATInfect2008_64.exeexe 321616d2313b1e477c466cbaaad8010f610bf19f9c8e219c0b2f9c71ea33ec89n/a 
2026-01-17IATInfect2008_64.exeexe 3de2729a75d3019d2c6159f4342b68c32a637f95a186fbd081bc4828934e4e59n/a 
2024-12-07n/aexe 58be2f77908a38e2ab7120837ba4985d3ba6b3dbe43e872ae039c69cdbc947ddVirustotal results 55.56%