URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.253.44/re.bot.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3474302
URL: http://87.120.253.44/re.bot.mips
URL Status:Offline
Host: 87.120.253.44
Date added:2025-03-12 01:30:04 UTC
Last online:2025-03-29 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-03-12 01:31:07 UTC to abuse{at}neterra[dot]net)
Takedown time:17 days, 5 hours, 28 minutes Bad (down since 2025-03-29 06:59:19 UTC)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-16n/aelf ac61fe040ab4b5679119b4bb6292fe940170c4511f1da3e780292bbac1a044f6n/aMirai
2025-03-16n/aelf 1f68cc875bb403f8abf495b4c032572ad93b79304e89f4750a2e12f2b820586en/aMirai
2025-03-14n/aelf 7c4da6ca887c3bb2a03c11a90e21057c1f2ef48f6f9e760ffe7c5401592bf201n/aMirai
2025-03-13n/aelf 577241bd5a4d09409b196824648cc0482ef4f37d7c77b0cec2cc44d91285716an/aMirai
2025-03-12n/aelf 17ff9a0db36dd48f93b56141b7390842cf7c3f76f15b6d8315eb25a1e569c04an/aMirai