URLhaus Database

You are currently viewing the URLhaus database entry for https://103.116.190.93/live.lnk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3562404
URL: https://103.116.190.93/live.lnk
URL Status:flame Online (spreading malware for 7 months, 1 days, 3 hours, 16 minutes)
Host: 103.116.190.93
Date added:2025-06-16 06:38:09 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-06-16 06:39:09 UTC to info[dot]btf{at}umgroups[dot]com)
Tags:lnk ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-12live.lnklnk 1f0df34152288c03f9383240f01bb0f2883bc4f2fcfd2f472a99225a025fa790n/a
2025-10-01live.lnklnk 2dd90a578f033e6ffdc81b983a3f88215d2daa127eaf96e61ddeed4d19fe67ffn/a 
2025-07-20live.lnklnk 9078e993b25a15b827c9a99229f2c4b6b99ec0df27be1c5df8436e5bfccfdccbn/a
2025-07-07live.lnklnk fb012901ec8da169ea21376665f2521280c0eb5ddc5a2efbca12d0828dd9019en/a 
2025-07-01live.lnklnk 04bef66527efb092670491750e280c8d2e3cb47bf82ba32e39567cd7e4570980n/a 
2025-06-16live.lnklnk b91e7d9e274b89d30f985dc97475fa8fb9cc34dec6cb680373ccfa78643540c1Virustotal results 14.29%