URLhaus Database

You are currently viewing the URLhaus database entry for http://141.98.11.129/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3346993
URL: http://141.98.11.129/ppc
URL Status:Offline
Host: 141.98.11.129
Date added:2024-12-13 00:47:07 UTC
Last online:2024-12-16 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-12-13 00:48:12 UTC to admin{at}serveroffer[dot]lt)
Takedown time:3 days, 21 hours, 15 minutes Bad (down since 2024-12-16 22:03:41 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-16n/aelf f46e00a03c166d2b1c8bc16b1045817e13cb3e632b9806914631069cbf49221an/aMirai
2024-12-16n/aelf 2001c2006c3be593241787e83741e51cfa9034e3727b69e5f6b1675c74fff73bn/a
2024-12-15n/aelf 89e41f9d8113f9434c02c64d0d3482b2fd8b8c8a3554d0eac51f40b2249b7c03n/aGafgyt
2024-12-15n/aelf db423d0533cd68ae34b599d4d0d511a5a3e4cd32d53a66542362471e9e6e9635n/aMirai
2024-12-14n/aelf 3f60481e7ddd23e3a20cff5930710474591bf3b68eb0d6d35fc96ad698156496Virustotal results 23.81%Gafgyt
2024-12-13n/aelf 4e114c1111ecdaf0a7622a347c025cd3f9584be170b129113d836a2a5a7c169fVirustotal results 57.14%Mirai