URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.238/lx/apep.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1919777
URL: http://5.181.80.238/lx/apep.arm
URL Status:Offline
Host: 5.181.80.238
Date added:2021-12-25 10:35:29 UTC
Last online:2021-12-27 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2021-12-27 10:51:49 UTC to noc{at}4vendeta[dot]com)
Takedown time:2 days, 0 hours, 59 minutes Poor (down since 2021-12-27 11:37:08 UTC)
Tags:DDoS Bot elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-26n/aelf 4162d361cc604bd9a7b9cec1e1c3d37dfda90250db61ccd64c48206c5aabc2f3n/a 
2021-12-25n/aelf 9044d8d7d2ad9f2571a8a1667da57b8a6a660a0afe42853155c85e6fa39e4bcfn/a 
2021-12-25n/aelf 0debccb77584d00de7878c29cafcf0d1af058c5c629b7cb29501f72acb1a5a3dVirustotal results 57.63%