URLhaus Database

You are currently viewing the URLhaus database entry for http://31.220.3.140/ri/la.bot.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2765431
URL: http://31.220.3.140/ri/la.bot.x86_64
URL Status:flame Online (spreading malware for 2 years, 6 months, 15 days, 17 hours, 55 minutes)
Host: 31.220.3.140
Date added:2024-02-20 12:00:15 UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2024-02-20 12:01:17 UTC to abuse{at}koddos[dot]com)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-27n/aelf 589b4a0dda2510fba387e41677898bb4d596f8676944fb24b3130f5434d0c04cn/a 
2024-02-25n/aelf 045bd8e5a794205b5c90240f2db2bd657e0e94de46ca8bb4e9db9c2daddbe616n/a 
2024-02-24n/aelf e9298f30c4ced307bd2a7b58a4c21b6e2d0f3c451a23369bfb1b8d1c7cd373b8n/a 
2024-02-22n/aelf 7206af8b8ee291801a1567ec8aa9cfedd659a29ac11f25bc44d2aab7cc266903n/a 
2024-02-22n/aelf 13aecadd50f3be098becc79ef648414182116fb4ec47726be1cad467f4ec09e0n/a 
2024-02-20n/aelf 585878729399e85fcb9728b98a0202cfb4bd2092d5f88fd998bdd0e934f83314Virustotal results 20.63%