Scan report · about 2 months agoPublic

nativebin.elephc.cloud

161.210.95.81AS402146 · US
Verdict

Looks safe

Automated

Our automated checks did not find known threat signals on this site at the time of the scan.

What to do

No action needed. Stay alert as usual — a clean result reflects this scan only, and sites can change after they are checked.

A clean result means no known threat signals were found in this scan — it is not an absolute guarantee, and a site can change after it is checked.

File

Stored by the engine

What you download may be live malware. Open it only in an isolated environment, and do not double-click it.

The ZIP is encrypted. Password:infected

Inside the ZIP the file carries a name the engine generated, not the one the page used.

Downloaded fileCleanThe engine stored it under a generated name

SHA-2568148de44d5d924f382702b5fe4b1d473b5ed7ea0dcff2c05c5e5e9db90628e94

Fromhxxps://nativebin[.]elephc[.]cloud/hook/516a5867c64f4a9d

Infrastructure

IP
161.210.95.81EXE-DEV - Bold Software Inc, US · AS402146US
TLS
CN=YE1, O=Let's Encrypt, C=US · expires Nov 6, 2026

WHOIS

Registrar
OVH sas
Created
Jun 17, 2026
Expires
Jun 17, 2027
Nameservers
mary.ns.cloudflare.comtodd.ns.cloudflare.com
13 malicious15 suspicious

Hashes & fingerprints

Page capture

Live

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Load
8.81 s · 1 requests
Stack · 1HSTS