URLhaus Database

You are currently viewing the URLhaus database entry for http://2.136.63.232:92/tftp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3520070
URL: http://2.136.63.232:92/tftp
URL Status:flame Online (spreading malware for 1 year, 1 month, 11 days, 21 hours, 59 minutes)
Host: 2.136.63.232
Date added:2025-04-20 20:36:06 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-20 20:37:09 UTC to nemesys{at}telefonica[dot]es)
Tags:elf tftp

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-16n/aelf 2e73a6d774fda3446cbcfa0f755b80b7e1625ec67e011346a70f89855c69b9f9n/a
2025-07-22n/aelf 979f7bc09f2096f7c30a1f3cfda7276f8dbfa29887e5c7591d4957293d4bbccan/a
2025-07-21n/aelf a6dfb29992ad42592e40c11c66a6389414919f145f3cabea21e91d9134463f53Virustotal results 6.35% 
2025-07-21n/aelf eee590448e159213bbf6899f20dfdb741902cfa295de6f8096ec244d18271923Virustotal results 38.10%
2025-07-18n/aelf a727990a1c8270912c7ea4f4199cc3fc9cc5aee3fb3d9d8693ba00ca7b4c8974Virustotal results 34.92% 
2025-07-18n/aelf 1d185fd8a14a5b61689e64f5dfefad24a93993281be6a9e9f257d23ea5eb40b8n/a
2025-05-07n/aelf 046c06cdab4dc1f4d02c2b7619fec397e9b21af5dd18c3e5cdab806931b77d75Virustotal results 22.22% 
2025-04-20n/aelf fe61d358d26d6d190c808ec8c76fa882fb4274dc46de5e10cf0cf07d51666594Virustotal results 24.19%