URLhaus Database

You are currently viewing the URLhaus database entry for http://68.183.165.105/.l/pty3 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1893173
URL: http://68.183.165.105/.l/pty3
URL Status:Offline
Host: 68.183.165.105
Date added:2021-12-17 12:16:33 UTC
Last online:2021-12-17 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: cocaman
Abuse complaint sent (?): Yes (2021-12-17 13:36:12 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 days, 14 hours, 11 minutes Bad (down since 2021-12-21 03:37:47 UTC)
Tags:CVE-2021-44228 elf log4j Muhstik Tsunami link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-19n/aelf 4a719439027a279b14a05d650691bed6e0a437ae87fb55895406616a55c6c720n/a 
2021-12-19n/aelf 9410e688cc3aaf18eb921a9fd1774c994d4ef59690a6b89e587485898af531bbVirustotal results 36.36% 
2021-12-17n/aelf 4c97321bcd291d2ca82c68b02cde465371083dace28502b7eb3a88558d7e190cVirustotal results 59.32%