TF-1932791
high
📛 Threat Title
Unknown malware: URL that delivers a malware payload http://211.101.233.147:8080/?a=w64&h=211.101.233.147&t=ws_&p=8080
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-09-25 11:47:16 UTC. Reporter: Kejult. Tags: Download, exe, payload.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://211.101.233.147:8080/?a=w64&h=211.101.233.147&t=ws_&p=8080
IOC database
- Type
- url
- Value
http://211.101.233.147:8080/?a=w64&h=211.101.233.147&t=ws_&p=8080- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-09-25 11:47:16 UTC. Reporter: Kejult. Tags: Download, exe, payload.
Remediations (10)
-
web:malwareanalyzer.com
MalwareAnalyzer by Cyble is a public malware analysis and threat intelligence platform. Submit a file, a URL , or a hash and get a verdict backed by multi-engine static scanning, real sandbox detonation, extracted indicators, and a threat graph you can pivot through.
-
web:malwarediscoverer.com
Our proactive system discovers URL redirections without human interference. Check out our research paper Discovering and Measuring Malicious URL Redirection Campaigns from Fake News Domains.
-
web:radar.cloudflare.com
Understand the security, performance, technology, and network details of a URL with a publicly shareable report.
-
web:smarturl.help
Scan suspicious URLs for dangerous schemes, payload -style destinations, and malware -oriented link indicators before sharing or opening them.
-
web:tools.malwaretips.com
Free security tools from the MalwareTips community. Scan URLs , check breaches, generate unbreakable passwords, and more.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:urlscans.com
This free malware URL scanner checks any link for malware and viruses in seconds and gives you a clear Safe, Suspicious, or Malicious verdict. When you scan a URL for malware here, we don't just do one blocklist lookup.
-
web:www.bubird.com
Home / Tools / Security Tools / Malware Link Scanner Malware Link Scanner Online Free Scan suspicious web links and unknown target URLs against known threat intelligence databases. Review threat signals and detect domain risks before visiting unverified web resources.
-
web:www.security.org
Our free link checker scans any URL for phishing, malware , and scam indicators in seconds. No sign-up required, and it works on links from email, text, or social media.
-
web:www.shadowserver.org
CRITICAL: Malware URL Report DESCRIPTION LAST UPDATED: 2025-09-24 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies URLs that were observed in exploitation attempts in the last 24 hours. They are assumed to contain a malware payload or serve as C2 controllers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.