URLhaus Database

You are currently viewing the URLhaus database entry for http://80.71.158.96/x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1995057
URL: http://80.71.158.96/x86_64
URL Status:Offline
Host: 80.71.158.96
Date added:2022-01-21 07:38:05 UTC
Last online:2022-04-17 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: info_sec_ca
Abuse complaint sent (?): Yes (2022-01-21 07:39:12 UTC to abuse{at}ntup[dot]net)
Takedown time:2 months, 26 days, 10 hours, 2 minutes Bad (down since 2022-04-17 17:41:52 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-25n/aelf 9030f1ab4fc3cf73fca1e7a5b5b86eb555b57c3ef86eca1c1ea88ee46888394cn/a 
2022-02-28n/aelf 9a2494974f03b732c469abcd3ed381362697ec0f0d3df2edc32a5f9ac6b643d0n/a 
2022-02-27n/aelf e4e3b1d16b3ed29ce1a37a67de8a0869622445040a4a9569008b40a245e5e92fn/a 
2022-01-26n/aelf 87cf8181de828a5213eae2d04921ccea18db1b0119c79111a7f2a8fbd8ccb905n/a 
2022-01-21n/aelf 2bd102ddc0e618d91a7adc3f3fb92fcfb258680f11b904bb129f5f2f918dcc5fVirustotal results 49.18%CoinMiner