URLhaus Database

You are currently viewing the URLhaus database entry for http://78.38.19.192:16739/i which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3571094
URL: http://78.38.19.192:16739/i
URL Status:flame Online (spreading malware for 1 year, 0 month, 28 days, 3 hours, 3 minutes)
Host: 78.38.19.192
Date added:2025-06-28 16:19:21 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-06-28 16:20:36 UTC to abuse{at}ito[dot]gov[dot]ir)
Tags:censys elf hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-19n/aelf d759bfd882a6e19267872f45585e94f95ad4de47f665c2a7353691cf6cd1662fn/a 
2025-09-24n/aelf 1961344e8c2d9070ab93711e47d59d89bce19d435513f496bebd6db86751e016Virustotal results 51.56% 
2025-08-10n/aelf f5b905e7a69341d834907e9d14ab1153da01d38ba7b7bb6beb1be11acd19392eVirustotal results 20.00% 
2025-08-09n/aelf 4dceb8a6ee56b92de37859f40f6a720ad6480653e2d669703bec1c4868055f7aVirustotal results 20.00% 
2025-06-28n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 74.60%Hajime