URLhaus Database

You are currently viewing the URLhaus database entry for https://103.116.190.93/uat.lnk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3562403
URL: https://103.116.190.93/uat.lnk
URL Status:flame Online (spreading malware for 7 months, 1 days, 10 hours, 57 minutes)
Host: 103.116.190.93
Date added:2025-06-16 06:38:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-06-16 06:39:09 UTC to info[dot]btf{at}umgroups[dot]com)
Tags:lnk ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-12uat.lnklnk 5d6a93001563c5667fc3c541a98cb93da56dcc4fe76943282f1688ca1b2e413fn/a 
2025-10-01uat.lnklnk f4586a9fb81fd82ff5ab373748955a30467ab045929a542f5cd74f73d8d1df9an/a 
2025-07-20uat.lnklnk 1911a018c35dae38a8df2364f02da79eddaf4cc1e61b93e5218caf18902fbb86n/a
2025-07-07uat.lnklnk e1047b0d9054a0a9433ba6371c0995b5a633091d0d2a7f741d68b3c84a6dd8ecn/a 
2025-07-01uat.lnklnk 5c0d039f7f6ed7f65505264e9498927439ac9b30acc661d8a0cd80106435add1n/a 
2025-06-16uat.lnklnk 971b87f49b6ca5c5d0c96efbb9105da3744d0f2706066378feb6ab565aa4c4c0n/a