URLhaus Database

You are currently viewing the URLhaus database entry for http://185.204.217.174/lx/a which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1909860
URL: http://185.204.217.174/lx/a
URL Status:Offline
Host: 185.204.217.174
Date added:2021-12-22 08:22:04 UTC
Last online:2022-01-03 08:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-02 15:47:52 UTC to abuse{at}cyberfolks[dot]pl)
Takedown time:11 days, 23 hours, 37 minutes Bad (down since 2022-01-03 08:02:11 UTC)
Tags:elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-27n/aelf eef82038b5662538aae79b39236132844b7627081766c0ff65cb23f90e84baa9Virustotal results 30.00% 
2021-12-25n/aelf 68aebc451c22cb49ce98cbb9322a30a3ac595b6c933c59ec6b8b16004b735a98n/aMirai
2021-12-23n/aelf 16cf5893b7a14ca57a3143d5eab7c1f7c54f0b2f31f3725c1981e819c014819dVirustotal results 45.16% 
2021-12-23n/aelf 64a88f696bd1564c7ac54384bfb6082463257bd516d2cc1d6b40b22395aee2a3n/a 
2021-12-22n/aelf b6b07f6c71f11c42878e9f394dde8ca9a7fb31b35bfdff4e3cee17d678ec2c4fVirustotal results 46.77%Mirai