URLhaus Database

You are currently viewing the URLhaus database entry for http://185.218.87.28/k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3538939
URL: http://185.218.87.28/k
URL Status:Offline
Host: 185.218.87.28
Date added:2025-05-08 20:15:09 UTC
Last online:2025-05-28 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-08 20:16:07 UTC to abuse{at}netiface[dot]co[dot]uk)
Takedown time:19 days, 4 hours, 10 minutes Bad (down since 2025-05-28 00:26:24 UTC)
Tags:gafgyt link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-20ksh f70949f8ab492aa75834b14846a16af412f5471a87137a52bbc04ccf4adf0227n/a
2025-05-20ksh 6a0fe54c76e78349c3bf111e34d5671008afc752bfcc4774921f8fe097d72379n/a
2025-05-16ksh d25edced6e2f469c654c4286437bc965fe5551e1987a33fd2e7b014281af929an/a
2025-05-10ksh 35b3cf0d0a9ebd67210bc9cd58b714476b13cae1dd5f2a82d76116bf1643d943n/a
2025-05-08ksh b0c37e60f541fdeed099ce65a49b7ff177f3c87e331bc6af7bc0fe5c994257den/a