URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.126/loki.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2759960
URL: http://5.181.80.126/loki.ppc
URL Status:Offline
Host: 5.181.80.126
Date added:2024-02-12 05:39:06 UTC
Last online:2024-02-16 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-02-12 05:40:09 UTC to noc{at}4vendeta[dot]com)
Takedown time:3 days, 21 hours, 11 minutes Bad (down since 2024-02-16 02:51:17 UTC)
Tags:32 elf mirai link PowerPC

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-14n/aelf 5d6d1cb5494c6c343c28d33dfa56d9f6443974f7f6a30fcf7b89d045183850a3n/a 
2024-02-14n/aelf 1bef841e94c00cad94dc5f3b4b072e5fa55829de8c766014eed1ccfe56e56294n/a 
2024-02-14n/aelf bb6785aff31d3bffc0c3a1298c485d5376eb5536b725813d24714ce48656a36fn/a 
2024-02-13n/aelf 8bfa8b5b6c9a26487e9dddd37a7752d05fa14b6f488a3f19e3735cef5fe2fed3n/a 
2024-02-13n/aelf 9f4ded040406fef0589dcf2e7114adf2ccb1f3ae3e6a7c58c5d4ee6db286ebd9n/a 
2024-02-12n/aelf 57e6e33c3994d3338f273bc0ad0a3e95886db94c6a28b007fbc8d229ab0be713n/a 
2024-02-12n/aelf 65484818c7056fcd0a49e32467ae8616d8e39223ae9541ed0fd16f1fed23aa2bn/a 
2024-02-12n/aelf b4894d5fdd132bd7b3b00e68f9a38ce4f0cc7ef7dec92f9b33ab4355a00cdea1n/a 
2024-02-12n/aelf 6ce0c78ddbeafb6b41d47ce8277485a9af6088fde73a80fd7c930d865cb4d682n/a 
2024-02-12n/aelf 925d57f5fe07cfde8b4a1cbe6ec5edcea4ad4648a4a3a9a21863acfb61a2fb55Virustotal results 22.58%Mirai