URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/o.xml which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704793
URL: http://41.216.189.110/00101010101001/o.xml
URL Status:Offline
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Last online:2025-11-18 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:4 days, 22 hours, 35 minutes Bad (down since 2025-11-18 21:14:27 UTC)
Tags:geofenced opendir sh ua-wget USA xml

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-17o.xmlsh 108b6645d86b0575e1dcd9cd0a35f77888243dc58e219cbaead8b48f76bdab6fn/a
2025-11-17o.xmlsh 68eb36390a8598290ed9e84449ac74ee8eb0070dda1ccab95656dd8f8c89bc07Virustotal results 13.11%
2025-11-15o.xmlsh 033dcb22a727ab8ddcae53eafedf19736a768267c50113108e2e9cb6c8b91848n/a
2025-11-13o.xmlsh d003791449d9bf3b7e20e72451a52aeb637c819a50c38af339feedc873009f91n/a