URLhaus Database

You are currently viewing the URLhaus database entry for http://187.68.43.14:42172/Mozi.a which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:705557
URL: http://187.68.43.14:42172/Mozi.a
URL Status:Offline
Host: 187.68.43.14
Date added:2020-10-17 04:05:14 UTC
Last online:2020-10-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: lrz_urlhaus
Abuse complaint sent (?): Yes (2020-10-17 04:06:28 UTC to abuse{at}lacnic[dot]net)
Takedown time:6 days, 5 hours, 37 minutes Bad (down since 2020-10-23 09:44:00 UTC)
Tags:elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23n/aelf 408de3f2c0b18f3e3a62a8a4b4ba2788951f0153c038333d39ce01cb916a06d7Virustotal results 27.87% 
2020-10-21n/aelf 53e6c6c9c94a201dfd04d1ac47401cdb032bdb520f019fa333946383be97f41aVirustotal results 30.91% 
2020-10-21n/aelf a215a991b5497e3ffcaf0d0966cd6a101ab8b3b257ef3313a309257f63768c0cVirustotal results 26.67% 
2020-10-19n/aelf daaf15d5d51ec4a54e072691c15fc39a544a53658a63d4c7b06a2070ee76cc60Virustotal results 25.42% 
2020-10-17n/aelf 4e14104f0fe7ab6c43a4cf8e209adb688e30d1380239bc107c5042883b05bb4cVirustotal results 20.00% 
2020-10-17n/aelf 9e0a15a4318e3e788bad61398b8a40d4916d63ab27b47f3bdbe329c462193600Virustotal results 61.67%Mirai