URLhaus Database

You are currently viewing the URLhaus database entry for http://211.204.100.20:1234/upm2008.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3335166
URL: http://211.204.100.20:1234/upm2008.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 26 days, 0 hours, 30 minutes)
Host: 211.204.100.20
Date added:2024-12-07 14:38:24 UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-07 14:39:33 UTC to irt{at}nic[dot]or[dot]kr)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-11upm2008.exeexe e8600c6e28b24a05f65d2687ed80f02649ec220651acad04ecedb7d668574955n/a
2026-01-18upm2008.exeexe df89963624b7dd0dfb33275677f8763d5596fe9f0ee73ac3f96164f7937e8be8n/a 
2026-01-18upm2008.exeexe c6e06daebc7f6e40705394f14cc473b8df42c62870fa16ad05624456276b1805n/a 
2026-01-17upm2008.exeexe 79cac67f08c2f59b60a127dab5630685d80e2dbf49eb9eaa6105f6f5b4a96533n/a 
2024-12-07n/aexe 5df5683c1d9972b31e8bbe48e48690a76d81817941b85883e9e79423fe65db21Virustotal results 19.18%