http://95.216.64.240:1224/client/36/700

Classification: Malicious

http://95.216.64.240:1224/client/36/700 is a malicious URL. Linked to Invisibleferret malware. Reported by 2 threat sources, last seen 2026-07-16.

Current activity

  • Offline — no longer resolving. Last online 2026-07-16 04:35:03.
  • Malware distribution — This indicator is distributing malware.

MITRE ATT&CK associations

Malware families: INVISIBLEFERRET (S1245)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malware Download URLhaus Abuse.ch 2026-07-16 04:26:13 2026-07-16 04:26:13 malicious-activity malware
InvisibleFerret ThreatFox Abuse.ch 2026-07-15 22:51:07 2026-07-15 23:25:04 malicious-activity S1245 InvisibleFerret

Tags

contagiousinterview dprk invisibleferret lazarus

URL information

Direct IP
95.216.64.240 — this URL points straight to an IP address, a strong indicator of malicious use.
SHA-256
3949538706d2c179fe650dd6e271ea912ed3770dd088d06d32c5a2c49c85b999
First indexed
2026-07-15 23:25:04
Last updated
2026-07-16 04:35:04
Last online
2026-07-16 04:35:03