URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.115.216/bins/xnxnxnxnxnxnxnxnaarch64xnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688033
URL: http://196.251.115.216/bins/xnxnxnxnxnxnxnxnaarch64xnxn
URL Status:Offline
Host: 196.251.115.216
Date added:2025-10-26 17:00:17 UTC
Last online:2025-10-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-10-26 17:01:18 UTC to abuse{at}nybula[dot]com)
Takedown time:4 days, 18 hours, 7 minutes Bad (down since 2025-10-31 11:09:04 UTC)
Tags:elf ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-28n/aelf 4919c7a86c0e70b77424e93a7ffedab6f78efe73f272906f4401e20e17f38d49Virustotal results 10.94%
2025-10-28n/aelf 18316148ebf382c1618f82576538591a3b07a1d36b913dc93f78ba3401a95d37n/a
2025-10-28n/aelf 5683fd10065462890f8f481a8e55595883e1025d3d211164bcac8266d9aedf2bn/a
2025-10-26n/aelf b0e10105327534786c62ad3082d87ae21d1203f24865dc8ecb86e212ad506715n/a