http://95.216.64.240:1224/client/36/700
Classification: Malicious
http://95.216.64.240:1224/client/36/700 is a malicious URL. Linked to Invisibleferret malware. Reported by 2 threat sources, last seen 2026-07-16.
Current activity
- Offline — no longer resolving. Last online 2026-07-16 04:35:03.
- Malware distribution — This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: INVISIBLEFERRET (S1245)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malware Download | URLhaus Abuse.ch | 2026-07-16 04:26:13 | 2026-07-16 04:26:13 | malicious-activity malware | |
| InvisibleFerret | ThreatFox Abuse.ch | 2026-07-15 22:51:07 | 2026-07-15 23:25:04 | malicious-activity | S1245 InvisibleFerret |
Tags
contagiousinterview dprk invisibleferret lazarusURL information
- Direct IP
- 95.216.64.240 — this URL points straight to an IP address, a strong indicator of malicious use.
- SHA-256
3949538706d2c179fe650dd6e271ea912ed3770dd088d06d32c5a2c49c85b999- First indexed
- 2026-07-15 23:25:04
- Last updated
- 2026-07-16 04:35:04
- Last online
- 2026-07-16 04:35:03