www.mediafire.com
Classification: Whitelisted
www.mediafire.com is a whitelisted (trusted) hostname. Reported by 10 threat sources, last seen 2026-09-02.
Current activity
- Offline — no longer resolving. Last online 2026-09-02 10:00:15.
- Command & Control server — Used by cybercriminals to control victim computers.
- Malware distribution — This indicator is distributing malware.
- Phishing — Hosts a phishing site and is intrinsically malicious.
- Stores phishing content — Phishing resources are hosted here.
MITRE ATT&CK associations
Malware families: NETWIRE (S0198) GULOADER (S0561) AGENT TESLA (S0331) REDLINE STEALER (S1240) LUMMA STEALER (S1213) AZORULT (S0344) NJRAT (S0385) AMADEY (S1025) ASYNCRAT (S1087) POWERSTATS (S0223) REMCOS (S0332) DCRAT (S9017)
Blacklist sightings showing the 100 most recent of 126
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Suspicious URL | Triage | 2026-04-26 22:02:20 | 2026-09-02 09:17:42 | anomalous-activity malicious-activity | |
| Asyncrat | Triage | 2026-02-09 12:34:03 | 2026-09-01 13:19:29 | malicious-activity | S1087 AsyncRAT |
| Umbral | Triage | 2026-03-29 05:26:36 | 2026-09-01 11:04:24 | malicious-activity | |
| Quasar | Triage | 2026-02-15 07:39:15 | 2026-08-31 15:46:04 | malicious-activity | |
| Darksiderat | Triage | 2026-08-29 16:39:28 | 2026-08-29 16:39:28 | malicious-activity | |
| Milleniumrat | Triage | 2026-02-10 11:08:59 | 2026-08-28 15:36:45 | malicious-activity | |
| Sheetrat | Triage | 2026-01-31 19:06:29 | 2026-08-28 15:21:11 | malicious-activity | |
| Vidar | Triage | 2026-01-30 22:53:19 | 2026-08-26 20:26:30 | malicious-activity | |
| Malware Download | URLhaus Abuse.ch | 2022-02-14 10:15:15 | 2026-08-25 08:53:13 | malicious-activity malware | |
| Salatstealer | Triage | 2026-01-30 19:59:57 | 2026-08-24 09:14:33 | malicious-activity | |
| Xworm | Triage | 2026-02-10 17:21:12 | 2026-08-19 19:33:22 | malicious-activity | |
| Overlord | Triage | 2026-08-19 18:59:07 | 2026-08-19 18:59:07 | malicious-activity | |
| Top Popularity Site | Cisco Umbrella | 2022-07-18 21:02:12 | 2026-08-17 17:32:40 | benign | |
| Luna_stealer | Triage | 2026-03-24 17:51:50 | 2026-08-17 03:31:22 | malicious-activity | |
| Discordrat | Triage | 2026-02-18 19:37:56 | 2026-08-14 19:04:53 | malicious-activity | |
| Xmrig | Triage | 2026-01-30 21:59:00 | 2026-08-13 23:24:04 | malicious-activity | |
| Dcrat | Triage | 2026-08-08 20:25:56 | 2026-08-08 20:25:56 | malicious-activity | S9017 DCRAT |
| Killmbr | Triage | 2026-08-05 23:19:48 | 2026-08-05 23:19:48 | malicious-activity | |
| Xenorat | Triage | 2026-08-03 19:15:45 | 2026-08-03 19:15:45 | malicious-activity | |
| Dracula_stealer | Triage | 2026-08-01 21:31:34 | 2026-08-01 21:31:34 | malicious-activity | |
| Silentnet | Triage | 2026-06-13 20:15:39 | 2026-07-27 21:49:43 | malicious-activity | |
| Xorium_stealer | Triage | 2026-06-14 16:34:21 | 2026-07-26 17:23:07 | malicious-activity | |
| Stealc | Triage | 2026-01-31 23:32:42 | 2026-07-26 16:56:40 | malicious-activity | |
| Ratonrat | Triage | 2026-06-19 00:26:23 | 2026-07-19 11:09:11 | malicious-activity | |
| Onyxc2 | Triage | 2026-07-09 04:17:02 | 2026-07-09 04:17:02 | malicious-activity | |
| Lumma | Triage | 2026-03-13 01:36:55 | 2026-07-04 20:55:34 | malicious-activity | |
| Stormkitty | Triage | 2026-03-22 02:45:40 | 2026-07-03 18:26:47 | malicious-activity | |
| Remus_stealer | Triage | 2026-06-28 08:28:52 | 2026-06-28 08:28:52 | malicious-activity | |
| Donutloader | Triage | 2026-02-11 08:24:23 | 2026-06-25 14:10:41 | malicious-activity | |
| Neptunerat | Triage | 2026-06-22 19:50:35 | 2026-06-22 19:50:35 | malicious-activity | |
| 751stealer | Triage | 2026-06-20 12:03:20 | 2026-06-20 12:03:20 | malicious-activity | |
| 888rat | Triage | 2026-06-20 04:16:31 | 2026-06-20 04:16:31 | malicious-activity | |
| Blankgrabber | Triage | 2026-03-22 10:51:33 | 2026-06-14 20:00:17 | malicious-activity | |
| Facebook phishing | Maltiverse | 2026-01-14 12:43:36 | 2026-05-22 01:01:39 | malicious-activity | T1566 Phishing |
| Sality | Triage | 2026-05-11 21:09:41 | 2026-05-11 21:09:41 | malicious-activity | |
| Remcos | Triage | 2026-01-31 22:38:41 | 2026-05-09 19:44:44 | malicious-activity | S0332 Remcos |
| Arsink | Triage | 2026-05-09 15:36:19 | 2026-05-09 15:36:19 | malicious-activity | |
| Skuld | Triage | 2026-04-10 05:30:28 | 2026-05-02 09:30:31 | malicious-activity | |
| Santa_stealer | Triage | 2026-04-20 18:00:06 | 2026-04-25 15:05:36 | malicious-activity | |
| Malicious URL | Triage | 2026-01-30 18:32:25 | 2026-04-21 12:40:17 | malicious-activity | |
| Mercurialgrabber | Triage | 2026-04-03 22:04:34 | 2026-04-03 22:04:34 | malicious-activity | |
| Wall_stealer | Triage | 2026-03-24 19:48:08 | 2026-03-28 15:22:09 | malicious-activity | |
| Metasploit | Triage | 2026-03-20 19:56:48 | 2026-03-20 19:56:48 | malicious-activity | |
| Generic Malware | Maltiverse Threat Observatory | 2026-02-02 18:10:07 | 2026-03-02 17:15:09 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Downloader.win32.generic | Maltiverse Threat Observatory | 2025-06-26 14:21:38 | 2026-03-02 07:21:41 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Trojan.generic | Maltiverse Threat Observatory | 2025-08-02 07:21:38 | 2026-03-02 07:21:41 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Asyncrat | Maltiverse Threat Observatory | 2026-03-01 06:05:09 | 2026-03-01 06:05:09 | country_code:co industry:education-and-nonprofits industry:manufacturing | S1087 AsyncRAT |
| Vidar | Maltiverse Threat Observatory | 2026-01-30 23:35:46 | 2026-02-28 13:10:07 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Exploit.generic | Maltiverse Threat Observatory | 2025-06-24 07:21:41 | 2026-02-28 08:21:42 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Trojan.js.generic | Maltiverse Threat Observatory | 2026-02-23 09:21:41 | 2026-02-24 12:21:40 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:technology-and-telecommunications | |
| Neshta | Triage | 2026-02-22 20:43:39 | 2026-02-22 20:43:39 | malicious-activity | |
| Njrat | Triage | 2026-02-16 00:34:42 | 2026-02-17 00:28:19 | malicious-activity | S0385 njRAT |
| Njrat | Maltiverse Threat Observatory | 2026-02-16 02:10:08 | 2026-02-16 02:10:08 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | S0385 njRAT |
| Xworm | Maltiverse Threat Observatory | 2026-02-11 19:10:08 | 2026-02-11 19:10:08 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Azorult | Triage | 2026-02-03 16:02:15 | 2026-02-03 16:02:15 | malicious-activity | S0344 Azorult |
| Remcos | Maltiverse Threat Observatory | 2026-01-31 23:05:09 | 2026-01-31 23:35:51 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | S0332 Remcos |
| Pup | Maltiverse Threat Observatory | 2025-06-23 10:21:37 | 2026-01-21 06:21:41 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | |
| Amadey | Maltiverse Threat Observatory | 2025-10-26 16:01:09 | 2025-10-26 16:01:09 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | S1025 Amadey |
| Powerstats | Maltiverse Threat Observatory | 2025-10-14 14:21:37 | 2025-10-15 11:21:36 | country_code:ar country_code:cl country_code:co country_code:ec country_code:es country_code:fr country_code:mx country_code:pe country_code:us industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications industry:transportation-and-logistics | S0223 POWERSTATS |
| 2025-06-11 20:46:11 | URLhaus Abuse.ch | 2025-06-12 00:07:02 | 2025-06-12 00:07:09 | malicious-activity | |
| Rhadamanthys | ThreatFox Abuse.ch | 2025-05-28 13:17:02 | 2025-05-28 13:17:02 | malicious-activity | |
| ClearFake | ThreatFox Abuse.ch | 2025-02-27 15:17:04 | 2025-02-28 14:17:13 | malicious-activity | |
| Malicious URL | Hybrid-Analysis | 2023-05-23 21:45:03 | 2023-12-16 12:00:04 | ||
| Lumma Stealer | ThreatFox Abuse.ch | 2023-11-12 17:17:08 | 2023-11-15 18:17:11 | malicious-activity | S1213 Lumma Stealer |
| RedLine Stealer | ThreatFox Abuse.ch | 2022-07-31 21:18:35 | 2023-11-12 18:17:07 | malicious-activity | S1240 RedLine Stealer |
| URLhaus Abuse.ch | 2023-05-25 06:21:31 | 2023-06-08 07:18:16 | malicious-activity | ||
| 2023-06-01 05:49:12 | URLhaus Abuse.ch | 2023-06-01 06:20:41 | 2023-06-01 06:20:41 | malicious-activity | |
| Phishing | Phishtank | 2020-07-18 04:29:33 | 2022-12-07 12:20:10 | compromised malicious-activity | |
| Vidar | ThreatFox Abuse.ch | 2022-07-31 21:18:35 | 2022-07-31 21:18:35 | malicious-activity | |
| Safe Site | Cisco Umbrella | 2022-07-14 23:50:15 | 2022-07-14 23:50:15 | benign | |
| Unwanted Software | URLhaus Abuse.ch | 2022-04-05 11:15:41 | 2022-04-05 11:15:41 | malicious-activity | |
| Malware | Hybrid-Analysis | 2021-06-03 00:15:25 | 2022-01-24 05:45:43 | ||
| Gen:Variant.Razy | Hybrid-Analysis | 2020-06-14 21:15:06 | 2022-01-07 17:15:43 | ||
| Malicious site | Hybrid-Analysis | 2018-09-04 04:00:13 | 2021-12-21 10:15:41 | ||
| Gen:Variant.Midie | Hybrid-Analysis | 2021-11-13 20:45:10 | 2021-11-13 20:45:10 | ||
| Unsafe.AI_Score_99% | Hybrid-Analysis | 2020-07-21 12:30:41 | 2021-11-05 21:15:12 | ||
| PUP.Bundler | Hybrid-Analysis | 2021-10-28 01:16:09 | 2021-10-28 01:16:09 | ||
| Delf.DFQ | Hybrid-Analysis | 2021-07-29 15:15:56 | 2021-07-29 15:15:56 | ||
| VB:Trojan.Emeka | Hybrid-Analysis | 2021-06-08 14:30:34 | 2021-06-08 14:30:34 | ||
| Malware Download | Abuse.ch | 2019-01-15 06:01:06 | 2021-04-30 16:15:44 | malicious-activity | |
| Generic.Malware | Hybrid-Analysis | 2018-06-09 23:15:53 | 2021-04-30 11:15:35 | ||
| Malware.Generic | Hybrid-Analysis | 2019-08-17 10:00:06 | 2021-04-21 18:17:11 | ||
| Riskware.Wacapew | Hybrid-Analysis | 2021-04-14 09:16:00 | 2021-04-14 09:16:00 | ||
| BehavesLike.Generic | Hybrid-Analysis | 2021-04-05 10:15:44 | 2021-04-05 10:15:44 | ||
| Malware.Heuristic | Hybrid-Analysis | 2021-03-19 02:17:28 | 2021-03-19 02:17:28 | ||
| Malware site | Hybrid-Analysis | 2019-07-25 09:45:06 | 2021-03-17 13:16:44 | ||
| Phishing site | Hybrid-Analysis | 2021-03-07 01:15:46 | 2021-03-07 01:15:46 | ||
| AgentTesla | Maltiverse Research Team | 2020-05-15 04:17:06 | 2021-02-23 04:17:29 | malicious-activity | S0331 Agent Tesla |
| Trojan.Generic | Hybrid-Analysis | 2020-03-23 19:15:12 | 2021-02-05 00:30:28 | ||
| Banload.YNB | Hybrid-Analysis | 2020-06-19 08:45:10 | 2021-01-28 10:15:23 | ||
| Gen:Heur.PonyStealer.Cm0@FCE7 | Hybrid-Analysis | 2020-08-25 14:15:56 | 2020-08-25 14:15:56 | ||
| W32.AIDetectVM | Hybrid-Analysis | 2020-07-07 17:30:08 | 2020-07-07 17:30:08 | ||
| Phishing SF Express | Maltiverse Research Team | 2020-06-22 10:17:06 | 2020-06-25 13:17:35 | ||
| Phishing.A | Hybrid-Analysis | 2020-06-09 20:01:36 | 2020-06-09 20:01:36 | ||
| GuLoader | Maltiverse Research Team | 2020-04-28 17:17:05 | 2020-06-05 08:17:07 | S0561 GuLoader | |
| NetWire | Maltiverse Research Team | 2020-05-14 09:17:05 | 2020-05-14 09:17:05 | S0198 NETWIRE | |
| Alexa Top 1 Million | Maltiverse Research Team | 2020-05-03 16:35:14 | 2020-05-03 16:35:14 | ||
| Gen:Variant.Graftor | Hybrid-Analysis | 2020-03-09 07:30:19 | 2020-04-28 01:15:05 | ||
| GuLoader.VHIJ | Hybrid-Analysis | 2020-04-22 13:30:12 | 2020-04-22 13:30:12 | ||
| FileRepMalware | Hybrid-Analysis | 2020-04-21 11:30:07 | 2020-04-21 11:30:07 |
Tags
njrat agenttesla screenconnect 8387 aggah pw-2023 rar password-protected 1466 1212 1397 4155 1234 1122 1717 malware_download 1 phishing stealer vidar redline backdoor pua exe netwire compressed #adwind none encrypted 7z metamorfo rat downloader compressed executable covid19 keylogger darkcomet dll lummastealer 2244 2023 dropped-by-smokeloader lummac2 stealer risepro 4545 2024 zip archive 1703 xworm lzh 1885 pw-9486 lumma lazy malware fakecaptcha clearfake hijackloader mediafire js rhadamanthys ascii remcosrat pxrecvoweiwoei iso c2-monitor-auto formbook defense_evasion discovery execution persistence privilege_escalation ransomware spyware salatstealer credential_access pyinstaller trojan upx xmrig miner sheetrat sheet_uvxsrseuotuo remcos 27 donutloader stealc 8409916482 loader azorult infostealer installer n1 themida sup asyncrat default milleniumrat hostingc2-shellcode collection bootkit adware blankgrabber stormkitty feb - 10 yt antivm linux macos quasar office04 hacked xorium_stealer lammer vitima otario deerstealer 7121724767 discordrat rootkit neshta steam sheet_hypcqsrrwuzf 0c07h8t91463gi9m30 xbinder 5bb280749c244c430674af9e8b43080e c713cde305dcce1941630de70230310a 5e980d8fda4a7d11e8b4e57ff9eae1e0 metasploit acrstealer destiny_stealer 087f8e4d09f1d31b31c90d1c11834ca7 925657f3d56b36f516d3cb1d802ec6ff b784f677a0cf59726e1b05c2bc1fdd3a sheet_jzzvqjrgcgu exploit luna_stealer wall_stealer e0d735e466b9560d92902b2e0e38a588 umbral google b27c355f88cf7cedac56c2de955172d1 2a3d8fd54ba4da6a66a25f9b0d1be67f s8tghsrthbasrth1 evasion mercurialgrabber d0790313fefcb557b18268cd8fbc24ce d8003a514b2f67259964ebb16f45d6c2 impact 8337b715923756987a7066dd3fd29c24 s5tghsrtbasrth4 skuld pyarmor santa_stealer microsoft arsink android bazarai suricata sality costura packer swift sideload silentnet ratonrat 888rat 751stealer neptunerat xred dropped-by-amadey remus_stealer onyxc2 dropper jar office044 svcstealer run thirdrat dracula_stealer sheet_wvnkneyyxn xenorat mex killmbr wiper dcrat overlord dll-sideloading dotnet fake-cheat teamspeak valorant 5336c7eab1f98882313284147187d7d8 sheet_haqpanrjmyf darksiderat bomba_expressIP addresses resolved by this hostname
- 104.16.114.74 (2024-08-02 14:11:21)
- 104.16.113.74 (2024-08-02 14:11:21)
- 104.16.202.237 (2019-12-13 03:44:32)
- 104.16.203.237 (2020-03-03 04:07:13)
- 104.17.138.186 (2018-05-24 09:35:35)
- 104.17.139.186 (2018-05-24 09:35:35)
- 104.19.194.29 (2019-10-15 16:33:32)
- 104.19.195.29 (2019-10-15 16:33:31)
- 205.196.120.12 (2017-02-12 16:57:10)
- 205.196.120.13 (2017-02-12 16:57:10)
- 205.196.120.6 (2018-05-22 09:19:11)
- 205.196.120.8 (2018-05-22 09:19:11)
- 104.17.150.117 (2025-06-12 00:08:14)
- 104.17.151.117 (2025-06-12 00:08:14)
- 104.17.147.83 (2026-07-14 12:19:19)
- 104.17.148.83 (2026-07-14 12:19:19)
- 104.18.214.225 (2026-08-17 17:32:39)
- 104.18.213.225 (2026-08-17 17:32:39)
Whois information
- AS name
- AS13335 Cloudflare, Inc.
- Domain
- mediafire.com
- TLD
- com
- DNSSEC
- ['signedDelegation, unsigned']
- Nameservers
- KEN.NS.CLOUDFLARE.COM, LISA.NS.CLOUDFLARE.COM, ken.ns.cloudflare.com, lisa.ns.cloudflare.com
- Whois server
- whois.godaddy.com
- Registrant
- Cloudflare, Inc.
- Address
- DATA REDACTED
- City
- DATA REDACTED
- State
- TX
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- Domain created
- 2002-08-11 15:31:16
- Domain expires
- 2031-08-11 15:31:16
- First indexed
- 2017-10-17 22:24:23
- Last updated
- 2026-09-02 10:00:15