URLhaus Database

You are currently viewing the URLhaus database entry for http://45.202.35.24/oth/x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3270245
URL: http://45.202.35.24/oth/x86
URL Status:Offline
Host: 45.202.35.24
Date added:2024-11-01 20:45:07 UTC
Last online:2024-11-07 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-11-01 20:46:08 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 days, 17 hours, 57 minutes Bad (down since 2024-11-07 14:43:55 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-03n/aelf f3f90fe74dd6675a4d0d41ea21721272e162149f3245dc290c16e7a643a6d85aVirustotal results 18.46%Gafgyt
2024-11-02n/aelf fe99ebffc9edeae5100c8426a3e8be3d678f669d045c6bfa3d062da07a7c9fedn/aGafgyt
2024-11-02n/aelf afcbd94bbd2801967c7deb74ead3c6c5ff7d5663c54b444c9c2898430b151bc4Virustotal results 27.69%Mirai
2024-11-02n/aelf b8f452f8ce51d57b74a295408734b6c3d349fee02f2f39a2a5707e519632ba9fn/aMirai
2024-11-02n/aelf 8673c5208078ac5d4b78e64dea09a557f16982e8fd622458f46c68ca9519d18dn/aMirai
2024-11-01n/aelf 8f16717450574b3e15c1f912f5df60d25b0a1c10daabd787e648206d91f29260Virustotal results 56.06%Mirai