URLhaus Database

You are currently viewing the URLhaus database entry for http://154.216.17.109/jwwofba5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3298722
URL: http://154.216.17.109/jwwofba5
URL Status:Offline
Host: 154.216.17.109
Date added:2024-11-21 21:51:08 UTC
Last online:2024-11-27 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-11-21 21:52:08 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 days, 2 hours, 22 minutes Bad (down since 2024-11-27 00:14:13 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-23n/aelf 79e8aecdd5bb26931b9b2993ef2f3d51a6cf34f74d88dd2bb93fb65d2e9ceef7n/aMirai
2024-11-22n/aelf 9d5468f3af8e0e857cc7f386b899e0246724a4623e7226be88665d779b41c2aan/aMirai
2024-11-22n/aelf 8e7c6f27872f3305dc63a9dd244e6b2027d458d1e725cbc6104afc392d3fc1een/aMirai
2024-11-21n/aelf 8dfd875aa504b3b7b67691ad0cf2ab2f96d30877e9b1eb998c0fda67d197cb89Virustotal results 63.49%Mirai