URLhaus Database

You are currently viewing the URLhaus database entry for http://185.39.207.117/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3502651
URL: http://185.39.207.117/ppc
URL Status:Offline
Host: 185.39.207.117
Date added:2025-04-06 10:01:14 UTC
Last online:2025-04-17 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-04-06 10:02:19 UTC to abuse{at}globconnex[dot]com)
Takedown time:10 days, 21 hours, 30 minutes Bad (down since 2025-04-17 07:32:28 UTC)
Tags:gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf 053d6e52a3713feb0843e37934e9e516aeba14aa19d4de64d9c2bd3422ea586an/a
2025-04-14n/aelf 14bf250d6e60e1e57a4090e6294eb1c9daba463e63f1ea33c9b3805744314090Virustotal results 43.55%Gafgyt
2025-04-12n/aelf c9abf35428f14664cfb80997ea8cd281917ae78fb35431209c71c69e63a21daan/aGafgyt
2025-04-10n/aelf 673926c1dcc5a7aa4aecab792c69004a996832a7fe62a0925bb0aedb15e30776n/aGafgyt
2025-04-09n/aelf 51eb9aa9ca11c0f8be53a710cbc5b46a4fdbeb2073402d02cc298d4d152b2a46n/aGafgyt
2025-04-06n/aelf 335c4dc4d67fc2b6ac7a27ee215799e1954da64d3becfb8429d0bdf65e9018f2Virustotal results 39.06%Gafgyt
2025-04-06n/aelf 157d4120f52152e651ac13005b822d0847ec7f9932b57265f5d1f83363516514n/aGafgyt