URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.126/loki.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2759953
URL: http://5.181.80.126/loki.sh4
URL Status:Offline
Host: 5.181.80.126
Date added:2024-02-12 05:38:06 UTC
Last online:2024-02-16 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-02-12 05:39:05 UTC to noc{at}4vendeta[dot]com)
Takedown time:3 days, 21 hours, 17 minutes Bad (down since 2024-02-16 02:56:17 UTC)
Tags:32 elf gafgyt link renesas

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-14n/aelf 28a16181d52b8b00eec2e8aea0d2de301e02faf4a4801bbd1bf0eb8d70993f60n/a 
2024-02-14n/aelf 432d5c8f64c39d032d7a79aab19ad8e2bef5a5a2e6172337a746cf9a9f8027fcn/a 
2024-02-14n/aelf a83d55849f1d7d576323ec6c4ecbffb92904e053b8ca903023ab9324f0efd263n/a 
2024-02-14n/aelf de5a9cb7e29a7c4deb4b66198416fbeae58588811ca2ee3f35bfd7cb126324adn/a 
2024-02-13n/aelf e25705d28386e2e932fc5f4643660e0e8890f1c914e7c9afaf93cb14378f7d3fn/a 
2024-02-13n/aelf 088b7e1f60c8d1d6b59403fb96b923f13577199081dfa95d26b0a34cbc94d172n/a 
2024-02-12n/aelf fd5943b4e782e30bbe70630591bbe04635e48cb0a8d7a87edf2e7a2215522f41n/a 
2024-02-12n/aelf c7eac6369d09867c3b5842616771833a4d9ba42ca4f1f096e6b5dfccb0487454n/a 
2024-02-12n/aelf 68af38e8488efef2b000943644db693979206a38d7bb1d9589b0533c2b5277ben/a 
2024-02-12n/aelf 1b468c42375ebc2f79ae77fa301469cc08faff6cb843268fea113ced19755f42Virustotal results 30.65%Gafgyt