URLhaus Database

You are currently viewing the URLhaus database entry for http://2.180.35.231:56242/Mozi.m which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3216503
URL: http://2.180.35.231:56242/Mozi.m
URL Status:flame Online (spreading malware for 1 year, 8 month, 12 days, 7 hours, 38 minutes)
Host: 2.180.35.231
Date added:2024-10-06 12:53:12 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-12-20 07:40:31 UTC to abuse{at}ito[dot]gov[dot]ir)
Tags:elf hajime

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-16n/aelf d77e1ce9e868885da05e693892745c57d37adf132e1ba13a103b97aeb9d6edbeVirustotal results 54.84% 
2025-01-30n/aelf 46957327c696b8fdb0599c12dbaceb57b30a70a665217c2801f1ac4715e2dbe7Virustotal results 42.86% 
2025-01-29n/aelf bad9cff1b7c1176fca77b88a11dd5f915039c11aab2a85966431522e05b17788Virustotal results 51.61% 
2025-01-29n/aelf 17f503e3960aaf85955e2495becfcf1dfb1effd0a4b5c40c9cbf6b110637e879Virustotal results 50.79% 
2025-01-28n/aelf 7e7f2832236f44064c53b47c64e1d9016ec0cda58bcd20e1bf7a2424e8bfe42aVirustotal results 57.14% 
2024-10-06n/aelf a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3Virustotal results 76.19%Hajime