URLhaus Database

You are currently viewing the URLhaus database entry for http://103.174.73.190/tajma.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2818176
URL: http://103.174.73.190/tajma.sh4
URL Status:Offline
Host: 103.174.73.190
Date added:2024-04-19 10:38:07 UTC
Last online:2024-05-13 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-04-19 10:39:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:24 days, 4 hours, 35 minutes Bad (down since 2024-05-13 15:14:22 UTC)
Tags:elf gafgyt link mirai link skyline

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-06n/aelf a9040e3cd1a2f6d926b0b379b5541076144f03f26b75ce1af00c4d1d328266e8n/a 
2024-04-22n/aelf 394c0a19a8aee5c7cb28d6c7131a2e0e32dd4a963666fd14ff335b0dff5d1278n/a 
2024-04-22n/aelf 79db719274cdd8cf564cc2db8b58e7e586c0c9b61fccdf806b857a7ab81d0b3en/a 
2024-04-22n/aelf 354a4bb2f862e7721c2bac165a82e25247ad7cbaaa16fd27e79aa39143c01c11Virustotal results 46.77% 
2024-04-21n/aelf 9022abbf03028f338405b14727ff916219b62ea387596e9778e9ea14d15e1eb2n/a 
2024-04-21n/aelf c4cecab4301d42c286ff3746b53b67f324e7e4a75bc0863fd957488d7ea8f361n/a 
2024-04-21n/aelf 811a8a948525d85796a3c3557929930a88c43855b1907e796d15326fc5e6c1e4n/a 
2024-04-21n/aelf dbf9fe19f8c6975bf8e58d93870e96ddcb4a3e4f6d61b8d857e86a6b241c9409n/a 
2024-04-21n/aelf f954e4579ba8cc2db0ca99bcbafdf4b76dc2d848ba6b769c080d07ae36d4d2f6n/a 
2024-04-21n/aelf c101534d92396886fde95ef73111caa91cdb9ffcd0d14769ede83495129daca3n/a 
2024-04-19n/aelf b5500712029bd3da704163956ac8d2ed2e9965643fc85045a7d48d588b100b67Virustotal results 50.00%Mirai