URLhaus Database

You are currently viewing the URLhaus database entry for http://51.68.170.59/worming.png which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:73302
URL: http://51.68.170.59/worming.png
URL Status:flame Online (spreading malware for 7 years, 8 months, 3 days, 19 hours, 52 minutes)
Host: 51.68.170.59
Date added:2018-11-02 08:01:12 UTC
Threat:Malware download Malware download
Reporter: MJRooter
Abuse complaint sent (?): Yes (2018-11-02 08:02:04 UTC to abuse{at}ovh[dot]net)
Tags:exe Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-07worming.pngunknown f914b9eca1b06fac49b04ddc2c9e24e2832f75f84f97fbc7595e2f9ceaeb5645n/a 
2018-11-06n/aexe a9b00d12f7fa52209a8ead91bb595522effc0ab5e4dcfa02e0d145ae7ea1cb19Virustotal results 17.65% Trickbot
2018-11-05n/aexe dcb6a98460e39c51b02f7d47f77c4254022f98093283df4a9fce7a9ff1ec60e4n/a Trickbot
2018-11-02n/aexe 3931ab29bb9719491cb7b4a2829adac423d145fb2407df812ce07d50f820a975Virustotal results 10.45% TrickBot
2018-11-02n/aexe 2d34e277abeda00257253a473b284169d4519c033dc968f27b1e64f98a21ae65Virustotal results 41.18% TrickBot