URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.71.105/z/spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3588661
URL: http://196.251.71.105/z/spc
URL Status:Offline
Host: 196.251.71.105
Date added:2025-07-24 01:34:07 UTC
Last online:2025-07-30 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-07-24 01:52:14 UTC to abuse{at}cheapy[dot]host)
Takedown time:6 days, 21 hours, 35 minutes Bad (down since 2025-07-30 23:27:24 UTC)
Tags:elf ESP geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-26n/aelf b5beebbe846367e3b38d5093aba8eb568ea9511c2c82c8c5b1211a3ef86d1568Virustotal results 35.94%Mirai
2025-07-25n/aelf f2c40698ea993f8413020a2495f718f672bc391955d2f927281df24e2a473bdbVirustotal results 35.94%Mirai
2025-07-25n/aelf 5e2dffbca0581740befa09c4e3b6392bd3a62e4bbcbb1f13f8b12dae7a744569Virustotal results 35.94%Mirai
2025-07-25n/aelf e14d94dc7ece5bb7e72049dd9b7006021fb6f540cf68e8a95fabf9b5b480c1fdn/aMirai
2025-07-24n/aelf d3bc8f3632225d05b292bc963e71f4b69641d23a196e43374c27814580ac1712Virustotal results 53.12%Mirai