URLhaus Database

You are currently viewing the URLhaus database entry for http://42.112.26.36/zd/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3472003
URL: http://42.112.26.36/zd/ppc
URL Status:Offline
Host: 42.112.26.36
Date added:2025-03-09 07:28:07 UTC
Last online:2025-04-07 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-09 07:29:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:29 days, 13 hours, 0 minutes Bad (down since 2025-04-07 20:29:13 UTC)
Tags:elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-26n/aelf 8903fe9cf6c0a39b21500c9379b7f6c2c16a1ae62215a38d73be579674fe8b63n/aMirai
2025-03-15n/aelf bed004af38c7f2ca314dab0d275591483efcd431639b7451c78f8f078e682d50n/aMirai
2025-03-11n/aelf 1879169e796665dcc47232c161f16c2b19e47495b388f34608b68a6074a45429n/aMirai
2025-03-09n/aelf 413e82d69b73217b4ad4cbe1f8c6ce6f80f7e26da703acb280c6429747b274ceVirustotal results 15.87%Mirai