URLhaus Database

You are currently viewing the URLhaus database entry for http://182.53.197.62/centaur-docs/23s which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1084420
URL: http://182.53.197.62/centaur-docs/23s
URL Status:Offline
Host: 182.53.197.62
Date added:2021-03-22 18:21:10 UTC
Last online:2022-08-08 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: hypoweb
Abuse complaint sent (?): Yes (2021-03-22 18:22:11 UTC to abuse{at}totisp[dot]net)
Takedown time:1 year, 4 month, 23 days, 19 hours, 46 minutes Bad (down since 2022-08-08 14:08:17 UTC)
Tags:elf groundhog

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-21n/aelf 4f02cc4d5426b63e3eca3ada3c9a8a111a952c0e373c5500519ea8eea5ade853n/a 
2021-04-17n/aelf 71ef590b32ef90a021be7bafd074b7698ffefab7f935e371568bef5eb2543f19n/a 
2021-04-09n/aelf f04440f915b9584c04582fe6517e47fe32019ebf9617b342a0396b6cf69f6f01n/a 
2021-03-29n/aelf 60d6733c1940b62f13cfe42d34c0c43aa73f3b8822d8c21cad5d3ebd6b9f94e2n/a
2021-03-25n/aelf 19f49c94e83ddfebd02212994df5d41b415a117b33cf864cc5571f23d563d86eVirustotal results 48.39%
2021-03-22n/aelf 6385b86b80ab8c43df5d6975a129edf940819b82bcaf6078edaa454704b44e03Virustotal results 54.10%