URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469827
URL: http://154.205.128.91/ppc
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:09:05 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-03-06 21:10:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 39 minutes Bad (down since 2025-04-16 14:49:59 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf ad8d3c2a0a489c3cffe8af4c7c20d509787e37392500eabb764e379dbde2c965n/aGafgyt
2025-04-14n/aelf 053d6e52a3713feb0843e37934e9e516aeba14aa19d4de64d9c2bd3422ea586aVirustotal results 40.32%
2025-04-14n/aelf 14bf250d6e60e1e57a4090e6294eb1c9daba463e63f1ea33c9b3805744314090n/aGafgyt
2025-04-12n/aelf c9abf35428f14664cfb80997ea8cd281917ae78fb35431209c71c69e63a21daan/aGafgyt
2025-04-10n/aelf 673926c1dcc5a7aa4aecab792c69004a996832a7fe62a0925bb0aedb15e30776Virustotal results 36.51%Gafgyt
2025-04-06n/aelf 335c4dc4d67fc2b6ac7a27ee215799e1954da64d3becfb8429d0bdf65e9018f2n/aGafgyt
2025-04-02n/aelf caa1621ea48e0134bd6edd637415138562b9ee4ac92e340c02838c26ef893b95n/aMirai
2025-04-02n/aelf ef3f79017876b42d1f3d7952fcfe041f1e28ae258fceb455ec7a074f834bcdfdn/aMirai
2025-03-29n/aelf 2c7110b5a549dbf2f7a9393d441b2e890acdd48273bb73b8807ec903e48a71f2n/a
2025-03-11n/aelf 3b04f71016bac2adada43a238563d28377e3ddea8a199da9d8510c77ec880a74n/aMirai
2025-03-09n/aelf 8fd1c9651b5e6cfe6e41350aeb2ec888e7a1f4e88863b253bd4232e6423174c9n/aMirai
2025-03-09n/aelf 0226dc432ae9be322e49628c3a7827f23cbd500bd4330e45187dc10d9f66e4e6n/aMirai
2025-03-06n/aelf 3baeff5d98b7c77f52c77be083ae2b5de45f3146e337c9662fccf71eae411133n/aMirai