URLhaus Database

You are currently viewing the URLhaus database entry for http://185.157.247.35/fx which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3376029
URL: http://185.157.247.35/fx
URL Status:Offline
Host: 185.157.247.35
Date added:2024-12-25 11:14:07 UTC
Last online:2025-01-08 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-12-25 11:15:19 UTC to noc{at}inovaperf[dot]fr)
Takedown time:14 days, 3 hours, 57 minutes Bad (down since 2025-01-08 15:12:46 UTC)
Tags:gafgyt link mirai link sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-29n/ash 9676aea60b4fbc50abaf49b824eca4fbb59b1ac12aa6e9501003a28eacdff910Virustotal results 11.48%Gafgyt
2024-12-27n/ash a02b076dd32c91403c500e9c8e8ee3fd36e29725f4bd3336e9d31b38a51a85b6n/aGafgyt
2024-12-27n/ash 56a83d7957560a6c8a77c87fff1219627f5d87f2be8009b5611bedfd88779b64Virustotal results 13.11%Gafgyt
2024-12-26n/ash 9b824561f92c7fb6c38c107f50901c7cdeb2021be37f77a4383b8d6e5b3ad675n/aMirai
2024-12-25n/ash 595aef3562d7599de9ff889b7793282596f8d7c4c3d5632e9c9021561b438962n/a