URLhaus Database

You are currently viewing the URLhaus database entry for http://80.71.158.96/xms which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1988945
URL: http://80.71.158.96/xms
URL Status:Offline
Host: 80.71.158.96
Date added:2022-01-19 08:54:04 UTC
Last online:2022-04-17 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: lrz_urlhaus
Abuse complaint sent (?): Yes (2022-01-19 08:55:17 UTC to abuse{at}ntup[dot]net)
Takedown time:2 months, 28 days, 8 hours, 40 minutes Bad (down since 2022-04-17 17:36:03 UTC)
Tags:sh shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01n/aunknown d36ec7212f8da1b8e0e72610934d16378eca1c1072cff6a0c645fa389d0f63a8Virustotal results 49.12% 
2022-03-26n/aunknown b7a8f32008b05b952e92d75310f09d5c7c7bf05142dd73adbb912a2419a71b89n/a 
2022-02-23n/aunknown 139ee356bd332b0094e301ff84d678801c43428fa6c91e80c50e2aa6932ea5d0n/a 
2022-02-21n/aunknown 7c60a9530869fea492b0d2307c9e03666d21765e280378685d51529042295752n/a 
2022-02-21n/aunknown 3351f8fabd5b20cc906d453294698306fd7bf796c96f49f3e1d2c8ba5bb32f93n/a 
2022-02-21n/aunknown 815da406a10009d9e743ed550b9133e0208e77c7a724f45b54d986d470483f7bn/a 
2022-02-20n/aunknown f5bd93d438aff73fbaf7d1a82db445c477e8de2dc6586965be365a7b3982392cn/a 
2022-01-25n/aunknown 77149437df40e0337f948022353f894e77a851f36999b7145cbfddf2c8f05359n/a 
2022-01-24n/aunknown 63320394c1016d52a461e3bebcc5e93a865f2242cb22fcd8ca0acec4c611d9a2n/a 
2022-01-19n/aunknown ab18e9ca70187c1794fc6a2b795108077206f2c9f8332149a42ceefb70dbee1eVirustotal results 50.00%