URLhaus Database

You are currently viewing the URLhaus database entry for http://195.24.237.73/bot which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3715325
URL: http://195.24.237.73/bot
URL Status:flame Online (spreading malware for 4 days, 8 hours, 16 minutes)
Host: 195.24.237.73
Date added:2025-11-23 20:37:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-23 20:38:14 UTC to hadihasanzadebashtiyan{at}gmail[dot]com,kotalwiya{at}proton[dot]me)
Tags:CoinMiner elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-27n/aelf 9eb0df432b5d759cc4ced9d8cc8fb9b109bc77b97085ab7d9f144a2dd3a6fddcVirustotal results 12.31%Mirai
2025-11-26n/aelf 40e302359cb9a80d373b75f1a3af0965e7da4ff590a0c110ee48f8fd84da6162n/aMirai
2025-11-26n/aelf c0c036e22f4a70ca1e57a0d24513aea1c205075fbe970f60b153a09f7cd0e450n/aMirai
2025-11-25n/aelf f5a7fd53488638cd3c36f39bdb6b9b35dc6df14ad837dd30eb87b95262feb2f5n/aMirai
2025-11-23n/aelf 54b916d05ab15bb3036571fcedcac9077cb2ac97a1631437c76635a695fda388Virustotal results 12.31%Mirai