URLhaus Database

You are currently viewing the URLhaus database entry for http://103.172.79.74/x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2764831
URL: http://103.172.79.74/x86_64
URL Status:Offline
Host: 103.172.79.74
Date added:2024-02-19 21:36:20 UTC
Last online:2024-03-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-02-19 21:37:13 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:26 days, 12 hours, 1 minutes Bad (down since 2024-03-17 09:38:20 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-17n/aelf fab7974744678a49f99a10d9843f345647e01573277e0ce5dbd07784c31cd399Virustotal results 46.03%Gafgyt
2024-03-13n/aelf 642211182634e9be9c048b693d757ef96f2ecd9af09b8a1365e7db9091abf28eVirustotal results 62.50%Mirai
2024-03-01n/aelf 5c851cf1c06e56cc6bc63b0ac154dc2a156a74787a085753c8bdc3a738f3fafbn/a 
2024-03-01n/aelf cf50ea0fd388282c48f95b4512478500726648d2f5e5dec6e9e8b0a95f397835Virustotal results 38.33% 
2024-02-27n/aelf 939b46a5a596896a869c1ac3f726b1d7483cffc6c0718ece9f62ff86412c71bdn/a 
2024-02-27n/aelf ecda58b2cd7bc3cfafdd04b22f46e84412e449b8590707e1b9014e303e0f48c1n/a 
2024-02-21n/aelf bb286f8e7b3c5ffa65afee2cc52645d25db6fc3a6dd43ee7ebe94d043dfd2d90n/a 
2024-02-20n/aelf 9f553570700f019ed6d50027b5eaad6817ba69912c67f21c626faa9d47ece2b9Virustotal results 67.74% 
2024-02-19n/aelf 9d0f87de4c4cda03364ea184070a9ec0ca994f48b460f1088b6aadbb32cc790dn/aMirai