URLhaus Database

You are currently viewing the URLhaus database entry for http://scan.504.su/i586 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740240
URL: http://scan.504.su/i586
URL Status:flame Online (spreading malware for 2 days, 2 hours, 6 minutes)
Host: scan.504.su
Date added:2025-12-22 15:23:21 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 15:24:19 UTC to abuse{at}lanedo[dot]net)
Tags:botnetdomain elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 963fae9d2208597b37ee527a00277cfaae067439fc16a99a70d58ec2a5898d68n/a
2025-12-24n/aelf fc8f611aae34e8166c07b3af6f76b500eb72b55843492ace8040fca3e29c51fan/aMirai
2025-12-24n/aelf e88fbee45cf9c2a0ca4c40571a48ed9145f256beeedaa6fea64279f0c22597ben/aMirai
2025-12-23n/aelf af191c549114af3f6fc0a4ad88d3deedf40dcbb877eb61e6ce55f29a87bb5333n/aMirai
2025-12-23n/aelf 85510dfe1a9fcfbad7a0ec22542cef21bd29a288f04951ab8c514c444f6b492an/aMirai
2025-12-22n/aelf 003ed20df0a5074d4d7db6000fa73a3a12d6fa4e10712ff4910be8bfe45780e1n/aGafgyt
2025-12-22n/aelf 5eccf4d0e8b651a35e4fc75428f786962cec26c59f7248ce133997e414a1da72n/aGafgyt