URLhaus Database

You are currently viewing the URLhaus database entry for http://37.220.123.125:45497/.i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3339161
URL: http://37.220.123.125:45497/.i
URL Status:flame Online (spreading malware for 1 year, 5 month, 23 days, 20 hours, 43 minutes)
Host: 37.220.123.125
Date added:2024-12-09 17:34:26 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-12-09 17:36:41 UTC to tac{at}umniah[dot]com)
Tags:censys elf hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-05n/aelf 365e43b99f9278301c1ecfd2ffd5dd10ae2d0bbce9a4fa75cbaefb5adbb5116bn/a 
2025-11-12n/aelf 36d0c7906d51e365f772c5dd0eed5d968f17c8839e7f967eddd28d809726cd1aVirustotal results 31.67% 
2025-10-08n/aelf c4e341049fea0013c789ffb925ed2a556fa833c1e564c1ce36de3098078268b1Virustotal results 21.67% 
2025-08-28n/aelf 8206c68f43001945dfeb365a6bbcd404997f6a1bf2454c681f6437c4f77412b4Virustotal results 37.88% 
2025-07-23n/aelf 4bc19d0619003756241694990c0c0b32c7a24207493e7aecb329566b03403af6Virustotal results 50.00% 
2025-06-16n/aelf 8cbab7327c76ca64cb2e9a55b57aaed7c704b914cbe8a284735cfa2f5c4ba7c7Virustotal results 40.00% 
2025-06-01n/aelf d0ee968875d6c56eb830b319fa896c0f236ac9152bc69ef4ed50ffdbdcf897b9Virustotal results 51.61% 
2025-05-15n/aelf 7ffa0b7435118c9f0d291097cd02fdeab4b304f93b51bcde6811559299c808e2Virustotal results 38.98% 
2025-05-14n/aelf ee606d13481f11805f83d6aede2e41545285249ce7919a2f8631a58c81467d25Virustotal results 20.00% 
2025-05-02n/aelf 1c4f16c21e12f0107aecb71d29f99c1b75c0a088e8ed306cab97f0fac165d7b3Virustotal results 48.44% 
2025-05-01n/aelf 104b5528b45a4458ff28e37f05777665f7a558ac5bbea295e8d6496fe0b63fe3Virustotal results 50.00% 
2025-03-19n/aelf 72677937334a9d862f96ecaffddbeda78e973923f31ee9102bf9d89f493b8cd9Virustotal results 21.67% 
2025-03-10n/aelf bf94ddf4b1171262e52ba7cf8edd3721d4a4cfc80f7e80f22fa107e8a4e61a0aVirustotal results 33.33% 
2025-02-28n/aelf eb11cfd160d3408c6dc4ff14a771dd9de877d4df33cc6213b5684c4e62c891bbVirustotal results 42.62% 
2025-02-03n/aelf 82a61a77ebfca0e93b2f916473835df16ae1e07f683d31fd2399f1a627b9b7e3Virustotal results 44.62% 
2024-12-27n/aelf b17a35d424753464e3210d6d9ab9f276c139020cfe298af54194c441a4e6b62dVirustotal results 23.33% 
2024-12-10n/aelf c3108ed96f471e7d66be4590d5472ef9bb0681bb16e809ed9dc1f98c8c2a56ecVirustotal results 38.10% 
2024-12-09n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 73.77%Hajime