URLhaus Database

You are currently viewing the URLhaus database entry for http://scan.504.su/powerpc-440fp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740228
URL: http://scan.504.su/powerpc-440fp
URL Status:flame Online (spreading malware for 2 days, 10 hours, 20 minutes)
Host: scan.504.su
Date added:2025-12-22 15:23:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 15:24:18 UTC to abuse{at}lanedo[dot]net)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 2d7bad74408c56563f32544c0ec91b56cae3c6afdaa4ad9aded41f1309996e86n/a
2025-12-24n/aelf ce6269661c097b7ecdec5550f1dce3b9269c3eb35af747d96024dbbf0e45c117n/a
2025-12-23n/aelf 7e3ba88133976eaee1d09f6166c60c87c6cceb7bd9771bff02a05139f182290fn/aMirai
2025-12-23n/aelf 44eb185d273aff8e9c05becb0f72bf09a5bd0ba365ccb3b18476251e473d03c3n/aMirai
2025-12-23n/aelf 9bac8f9209b487b949bfd7e609ba1cfb2564a97baf05360269a58fd0634b4737n/aMirai
2025-12-22n/aelf 6af21c2381c1078c46629386988ab032f9a31a341717d08c7ae7eadd06894ce5n/a
2025-12-22n/aelf e18d56796d521b52ead1af34d42432827f6cc4511619226389d6622d002ace9en/aMirai
2025-12-22n/aelf d5f8cd97c9934b17559179623aeb7b7a9ed580d9367c051bc92e83362af8ca25n/aMirai