URLhaus Database

You are currently viewing the URLhaus database entry for http://185.204.217.174/lx/2 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1943980
URL: http://185.204.217.174/lx/2
URL Status:Offline
Host: 185.204.217.174
Date added:2022-01-02 15:44:04 UTC
Last online:2022-01-10 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2022-01-07 13:21:37 UTC to abuse{at}cyberfolks[dot]pl)
Takedown time:7 days, 20 hours, 9 minutes Bad (down since 2022-01-10 11:57:02 UTC)
Tags:DDoS Bot elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-09n/aelf a260d43ee0aee133519e5ae313f526de2e93f30d18b705ddc1473b084f7f19b4n/a 
2022-01-06n/aelf 636e68661f1209d1e89891c9f5ca848a7a9a8e575835fa502d183851b66fb299Virustotal results 46.67%Mirai
2022-01-02n/aelf 34e9eed3fceb8ef9dbb369ff0cc1630fac8bfe22e387bbf5da6e85f1c4318c81Virustotal results 60.00%