URLhaus Database

You are currently viewing the URLhaus database entry for http://185.52.1.235/love/Demon.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:223180
URL: http://185.52.1.235/love/Demon.m68k
URL Status:Offline
Host: 185.52.1.235
Date added:2019-08-08 17:30:13 UTC
Last online:2019-08-14 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-08-08 17:32:03 UTC to abuse{at}routelabel[dot]net)
Takedown time:6 days, 4 hours, 51 minutes Bad (down since 2019-08-14 22:23:11 UTC)
Tags:bashlite elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-08-13n/aelf 4785b03ef67f85b39050dcec8e6ecf7b7a500c29cefb6fa08d32835d1ac2437fVirustotal results 41.18% 
2019-08-09n/aelf 8cf88104aecd1a2115bbce717ffc3c8d74d6cb01528ea0389ea141f065d2147en/a 
2019-08-09n/aelf f585f2e2975bd9ed003da6f0bd84e573b6d2a9ebdaca132aab4e755f840c1c24n/a 
2019-08-08n/aelf c6c09cebff99c62d1b905a80c83d29c53aa333f9f315046cf8dc2b2dab2d7309Virustotal results 43.86%