https://yelahaye.surf/api/v1/session
Classification: Malicious
https://yelahaye.surf/api/v1/session is a malicious URL. Reported by 2 threat sources, last seen 2026-08-11.
Current activity
- Offline — no longer resolving. Last online 2026-09-03 13:03:15.
- Malware distribution — This indicator is distributing malware.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Kongtuke | Maltiverse Threat Observatory | 2026-08-11 19:40:05 | 2026-08-11 19:55:04 | anomalous-activity country_code:ar country_code:us industry:education-and-nonprofits industry:government-and-public-sector industry:transportation-and-logistics malicious-activity malware | |
| Generic Malware | Maltiverse Threat Observatory | 2026-08-11 18:10:09 | 2026-08-11 18:10:09 | malicious-activity malware | |
| KongTuke | ThreatFox Abuse.ch | 2026-08-11 17:06:32 | 2026-08-11 17:25:04 | malicious-activity |
Tags
kongtuke tag-124 js.landupdate808URL information
- Hostname
- yelahaye.surf
- Domain
- yelahaye.surf
- TLD
- surf
- SHA-256
4e643c1038c4f2a969274fc163e2b01afa4389190c8b6867ffbb5ac275c24c79- First indexed
- 2026-08-11 17:25:04
- Last updated
- 2026-09-03 13:03:15
- Last online
- 2026-09-03 13:03:15