URLhaus Database

You are currently viewing the URLhaus database entry for http://103.174.73.190/tajma.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2818181
URL: http://103.174.73.190/tajma.ppc
URL Status:Offline
Host: 103.174.73.190
Date added:2024-04-19 10:38:07 UTC
Last online:2024-05-13 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-04-19 10:39:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:24 days, 4 hours, 25 minutes Bad (down since 2024-05-13 15:04:10 UTC)
Tags:elf gafgyt link mirai link skyline

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-06n/aelf db50b52e01196b25fb0dd970d2b34be19214540ff89050d909aadf7961480d86n/a 
2024-04-22n/aelf 2fb082ca5766f1122a74c3f0c37fd54794961dc9c5f8248803c6dd9faeb6b84dn/a 
2024-04-22n/aelf 6abb9bca9a2b226235f1ab175c105999c3f05cc87e15a893aca0577f20e498b6n/a 
2024-04-21n/aelf 639328141892fa8296785e1ed989270e2e0a1cc473bbc44bcf118e87b5c05a3dn/a 
2024-04-21n/aelf 13f347dd0b5813941e0417ecf124f73dae9010ee169d543e15507e94fcd7e51an/a 
2024-04-21n/aelf c235b5ad3831c9ef09883c9e5e9e5660fecb03a527dcad9e6086584b7336232cn/a 
2024-04-21n/aelf c9c6fcb7a2c6c25823fd1ed26f7bf13e27bf0c6d4f57bd79202f17879a0d7545n/a 
2024-04-21n/aelf 309710980ec8a4a1487321a3c1963221150feb5d509a06360df0df46f9c5b011n/a 
2024-04-21n/aelf 9b25a58df9f5a89525cd3f2c25a471d6f23ded0a206f063d3402e471a4e0d065Virustotal results 41.07% 
2024-04-21n/aelf 5a4eb777fb3928179ce73f0997ddae90e672fcd6776eb1e87c1a685cb7cee572n/a 
2024-04-19n/aelf 1b90358ecf1177533ed3138949c76714b4404f0b1b8bf27a84978bd1e0248e2fVirustotal results 45.31%Mirai