URLhaus Database

You are currently viewing the URLhaus database entry for http://188.12.100.131:30261/.i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3529934
URL: http://188.12.100.131:30261/.i
URL Status:flame Online (spreading malware for 1 year, 1 month, 3 days, 11 hours, 15 minutes)
Host: 188.12.100.131
Date added:2025-04-29 11:02:05 UTC
Threat:Malware download Malware download
Reporter: cesnet_certs
Abuse complaint sent (?): Yes (2025-04-29 11:04:07 UTC to abuse{at}retail[dot]telecomitalia[dot]it)
Tags:hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-09n/aelf 0267d1a79736e41e7aa40cbf186f8b0cf66bc978a35e9a0c16ad3a113ea7ba07Virustotal results 57.14% 
2025-05-08n/aelf dc91b49d88b4682bd44d491ce409cec2f61ce8c514fc704aeef0521c10808da5Virustotal results 55.56% 
2025-05-08n/aelf e54977e44c282dfd33e0f66190a0ee51079730168368c196e3f45177d1346c30Virustotal results 58.73% 
2025-04-29n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 76.19%Hajime