URLhaus Database

You are currently viewing the URLhaus database entry for http://27.124.17.179/1.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3847944
URL: http://27.124.17.179/1.dll
URL Status:flame Online (spreading malware for 11 days, 20 hours, 9 minutes)
Host: 27.124.17.179
Date added:2026-05-16 16:44:11 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-05-16 16:45:16 UTC to cs[dot]mail{at}ctgserver[dot]com)
Tags:27-124-17-179 ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-251.dlldll aa8700ef5cdd9c15a5b3b9083f32ad89127115d3cffde99d8dde441003062742n/a 
2026-05-191.dlldll 19c16cc3eb1b5ef814c652cb0b1ac2ae186ed98bddfccf050fb72abe073f808cn/a 
2026-05-161.dlldll ae6bb36316ba20413015d7879e2893a60af275e54dcf8ecc709af58e23f4e79fn/a