URLhaus Database

You are currently viewing the URLhaus database entry for http://85.239.33.65/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2828746
URL: http://85.239.33.65/mips
URL Status:Offline
Host: 85.239.33.65
Date added:2024-04-27 07:48:11 UTC
Last online:2024-04-30 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-04-27 07:49:07 UTC to abuse{at}alexhost[dot]com)
Takedown time:3 days, 5 hours, 31 minutes Bad (down since 2024-04-30 13:21:00 UTC)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-30n/aelf c84aecad472883b9c198248037fd5436a3f3f94eff3dbcc8c3a095cc21058018n/aGafgyt
2024-04-30n/aelf 4aa9ed17ff40954cf41b8fe59ad7c7a6fb433d5a60e1c5eb5e611a48df803be2n/a 
2024-04-27n/aelf 7d34301153de04af408508f314be861ef6f8b9c292649b454ecad4aa0c31ddb2Virustotal results 58.46%