URLhaus Database

You are currently viewing the URLhaus database entry for http://204.76.203.76//ZG9zarm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2264353
URL: http://204.76.203.76//ZG9zarm
URL Status:Offline
Host: 204.76.203.76
Date added:2022-08-03 11:04:04 UTC
Last online:2022-08-06 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2022-08-03 11:05:07 UTC to ryan{at}ohiocloud[dot]net)
Takedown time:2 days, 13 hours, 54 minutes Poor (down since 2022-08-06 00:59:16 UTC)
Tags:DDoS Bot mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-05n/aelf 3072cf73f53bc5c14785787380ce1794fca2c71141b67d63ddc4d864dd39714eVirustotal results 24.19%Mirai
2022-08-03n/aelf c9aac257b5675f76ae9f349a93603502c0b4711a7cda619552e2f00e76c5b87fVirustotal results 38.89% 
2022-08-03n/aelf d1a2784fe324bb26da9aa73d4ed21483c6e4868accc82315fc019064abe6f6d2Virustotal results 43.55%Mirai