URLhaus Database

You are currently viewing the URLhaus database entry for http://45.202.35.91/l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3280715
URL: http://45.202.35.91/l
URL Status:Offline
Host: 45.202.35.91
Date added:2024-11-07 15:23:08 UTC
Last online:2024-11-21 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: LemonHaze420_
Abuse complaint sent (?): Yes (2024-11-07 15:24:16 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:13 days, 10 hours, 15 minutes Bad (down since 2024-11-21 01:39:54 UTC)
Tags:mirai link shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-14n/ash 47b674a10b858e4d6708fc613030c3d98e4ff7fc3c25dfefb38366bb2ffeca30Virustotal results 22.22%
2024-11-10n/ash a909843aac250b8580f42dadcb806cd38a1157f96e2b93f8d94d7c3db9f9d2cbVirustotal results 19.35%Mirai
2024-11-09n/ash 7bad123032a0e9a4f6d7a399b7d7a171c24f505201186d679ca495ba936195bdVirustotal results 20.97%Mirai
2024-11-08n/ash 486bb184414a6bb37263ea568512e122fc35071a14edc1a0897e228ed98070c8Virustotal results 20.97%Mirai
2024-11-08n/ash becb09b3bdc89012d8332651976512f971234839ecb2d385e17988a67f2d9049Virustotal results 21.31%
2024-11-07n/ash de413fe89381ab759a056fd646a5afb82ba80bc6a0df6604db390bbaa847b2b7Virustotal results 21.31%
2024-11-07n/ash 082577cee4e185f4faebaa1f31c4739babf0569d4b3a0bd7e7453b4f5310a1faVirustotal results 20.97%Mirai