URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.115.216/bins/xnxnxnxnxnxnxnxnpowerpcxnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688022
URL: http://196.251.115.216/bins/xnxnxnxnxnxnxnxnpowerpcxnxn
URL Status:Offline
Host: 196.251.115.216
Date added:2025-10-26 17:00:11 UTC
Last online:2025-10-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-10-26 17:01:18 UTC to abuse{at}nybula[dot]com)
Takedown time:4 days, 18 hours, 12 minutes Bad (down since 2025-10-31 11:13:27 UTC)
Tags:elf ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-28n/aelf 9b23a5bc17ab4feb105b56f7384886233e73d53aa93ec1f8b37151de5f81331eVirustotal results 7.81%
2025-10-28n/aelf 7da16e4c7ebe84b198481ede18c91aa505867b267de62eac05c1cd5ff8b36815n/a
2025-10-28n/aelf edb7b5c9d15bf3826dc3d0a6c0eb0479331ce05142151d282c96f7dbb5e84f38Virustotal results 10.94%
2025-10-26n/aelf 09b00d0e69f788d823d3b39bef378eff05805cc3a623f9f9b3361ea663f01b6cn/a