URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469856
URL: http://154.205.128.91/zd/ppc
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:28:04 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:29:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 23 minutes Bad (down since 2025-04-16 14:52:08 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf a1858d198a6402c31429aa38e012c24a503ff84e9c614527a11d1a723b2d3806n/aMirai
2025-04-12n/aelf eccdd51e0085e474f9170d334c6444ccabc1748e2730e1f298228b07f2ebb907n/aMirai
2025-04-02n/aelf 2b80b0908022d56080dc5c70d7d2610cb8ded5954577d7d83e413e8dae133946n/aMirai
2025-03-25n/aelf 369a65073ad707d852bcb79cb41bbf6b6cf76a411470d099eda3f71acd39df8cn/aMirai
2025-03-11n/aelf 1879169e796665dcc47232c161f16c2b19e47495b388f34608b68a6074a45429n/aMirai
2025-03-09n/aelf 7f1065ac86cf0d5c79a53c30d3358438e378f9e162560977f8f477002090082dn/aMirai
2025-03-09n/aelf 413e82d69b73217b4ad4cbe1f8c6ce6f80f7e26da703acb280c6429747b274ceVirustotal results 9.52%Mirai
2025-03-06n/aelf 3570f2ff357223a12652e63a99753e55f3cb1b2f27010b62a6dd4855ae2747a9n/aMirai