URLhaus Database

You are currently viewing the URLhaus database entry for http://104.194.9.127/tt/powerpc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3461858
URL: http://104.194.9.127/tt/powerpc
URL Status:Offline
Host: 104.194.9.127
Date added:2025-03-01 09:47:09 UTC
Last online:2025-05-22 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-01 09:48:06 UTC to abuse{at}reliablesite[dot]net)
Takedown time:2 months, 21 days, 14 hours, 12 minutes Bad (down since 2025-05-22 00:00:42 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-20n/aelf aaa59a329b7d9ace426ce5afbfeb6b15f5a8010865de4bad68e3ec03aa1f5a59Virustotal results 58.73%Mirai
2025-03-01n/aelf 34a82b5e1ed69e37297a81462f93764622b69e53a49f0987bce2da4b8aac705aVirustotal results 53.97%Mirai