URLhaus Database

You are currently viewing the URLhaus database entry for https://209.250.2.244/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3748137
URL: https://209.250.2.244/
URL Status:flame Online (spreading malware for 4 months, 26 days, 6 hours, 33 minutes)
Host: 209.250.2.244
Date added:2026-01-01 12:53:29 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-01-01 12:55:28 UTC to admin{at}armourcloud[dot]io)
Tags:censys ClickFix ClickFix-cc html

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-265c8cf2a9dc75683293ca7d997ea22891a75b4c295871a0284eb0e66b6b5347d6.htmlhtml 5c8cf2a9dc75683293ca7d997ea22891a75b4c295871a0284eb0e66b6b5347d6n/a 
2026-02-23ede7636d66554d867fa36fbd4a318620d605ebf6b82ee5c1a9cdeb06be91b393.htmlhtml ede7636d66554d867fa36fbd4a318620d605ebf6b82ee5c1a9cdeb06be91b393n/a 
2026-02-220cc55c14c93da64e03e1cb366a1d6eb3486983cb06fa73cc27333f336175a1e5.htmlhtml 0cc55c14c93da64e03e1cb366a1d6eb3486983cb06fa73cc27333f336175a1e5n/a 
2026-02-22f8d16d2812a60de4a3e350e5a7a4103a10cddd75883df23a53b2d4fbdcb4ca5d.htmlhtml f8d16d2812a60de4a3e350e5a7a4103a10cddd75883df23a53b2d4fbdcb4ca5dn/a 
2026-01-05e075c2e1e700c7cb6611949c20f78191137a475cb3335f4648f62933f6c42733.htmlhtml e075c2e1e700c7cb6611949c20f78191137a475cb3335f4648f62933f6c42733n/a 
2026-01-0187d50c68099260e7113894399e76ac467f50775ead12ee88d4b7ab850fcda7bb.htmlhtml 87d50c68099260e7113894399e76ac467f50775ead12ee88d4b7ab850fcda7bbn/a