URLhaus Database

You are currently viewing the URLhaus database entry for https://159.203.9.141/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3748027
URL: https://159.203.9.141/
URL Status:Offline
Host: 159.203.9.141
Date added:2026-01-01 12:33:08 UTC
Last online:2026-05-27 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-01-18 02:48:12 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 months, 9 days, 17 hours, 6 minutes Bad (down since 2026-05-27 19:54:39 UTC)
Tags:censys ClickFix ClickFix-cc html

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-08d114d40ba5f58c9b51b198afd1e454422f6ba10ffe12867f9a68a2f9686515f4.htmlhtml d114d40ba5f58c9b51b198afd1e454422f6ba10ffe12867f9a68a2f9686515f4n/a 
2026-01-19ceec755d595e074cbf2a5a19b92f3f5b1c4c0cde8af6c04b8adf7eca0f01ea40.htmlhtml ceec755d595e074cbf2a5a19b92f3f5b1c4c0cde8af6c04b8adf7eca0f01ea40n/a 
2026-01-185e4b4e142235bfcd1d460e754700e18e1da60d9a8ae42e45e6ac9dd57296c983.htmlhtml 5e4b4e142235bfcd1d460e754700e18e1da60d9a8ae42e45e6ac9dd57296c983n/a 
2026-01-181766c6c1a93bc36eb43245fe32b8afcd8e78292ffb92c5266ff7bb95ab9a3d2f.htmlhtml 1766c6c1a93bc36eb43245fe32b8afcd8e78292ffb92c5266ff7bb95ab9a3d2fn/a