URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.102/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676951
URL: http://5.181.80.102/mips
URL Status:Offline
Host: 5.181.80.102
Date added:2023-07-05 09:27:05 UTC
Last online:2023-07-13 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2023-07-05 09:28:05 UTC to noc{at}4vendeta[dot]com)
Takedown time:8 days, 0 hours, 23 minutes Bad (down since 2023-07-13 09:51:30 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-12n/aelf 57de72c1a38a43dfe40b2d3bbef0a98c68c0a964c5d338065651a97919edae64Virustotal results 53.33%Mirai
2023-07-09n/aelf 46f1daf2cde03fc625db9bbeceaa17e4ec263c6414508dd0a638545859b823b4Virustotal results 50.82%
2023-07-09n/aelf 1fdabd1a37b864757caf2d597714378aa4b54a88f1e7cc45b93a737a9f3bd6den/a 
2023-07-09n/aelf a7478a6e2110390bd3d6bbafca19627cc1fc5a052c1136929f94b29dd39df4b4Virustotal results 50.88%
2023-07-07n/aelf dd7f76fc4193ec89f4b865f96cc382379a001299dc50d6ef0be086fd11c0db9an/a
2023-07-07n/aelf 3714209af20d168bac3107866bfb549e3d65936a0861a6867c5be4d12d491862n/a
2023-07-06n/aelf 4fb0b2a3175d1dc6d7892b0a97fef6500ac9aed5c2f11b90a805b2b6a6ba5059n/aMirai
2023-07-06n/aelf 7cd409e343d4d472da9184af96659b5b6a8f05d81ee3e2b3f3b938a445ea108cn/aGafgyt
2023-07-06n/aelf 12c99ef1e75fadd8ce9ca7767cc0c1b535de4a5f8231dfa5aaf37f1aa2770415n/a 
2023-07-06n/aelf 70ca7d462f92340bfdc8c89512a2471750d04a6fd70bac6d919dd3b409b96b67n/aGafgyt
2023-07-06n/aelf 593477fb6191cc3dd5a4c85676237c3d638997516c083ee2d242319ca71788ccn/a 
2023-07-06n/aelf 1516f8ca8c019c6a24991fbbcb6504788421304cfeec9483e48892b57c243642n/a 
2023-07-05n/aelf 099afbffc5868d5ea7eb0da38cf15ed782ff312faa4328e5138bcbe9ca783139n/a