URLhaus Database

You are currently viewing the URLhaus database entry for http://103.75.217.122:60256/Mozi.m which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:749052
URL: http://103.75.217.122:60256/Mozi.m
URL Status:Offline
Host: 103.75.217.122
Date added:2020-10-25 22:04:36 UTC
Last online:2020-11-10 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: lrz_urlhaus
Abuse complaint sent (?): Yes (2020-10-25 22:06:03 UTC to Abuse{at}northtelecom[dot]com)
Takedown time:15 days, 10 hours, 39 minutes Bad (down since 2020-11-10 08:45:18 UTC)
Tags:elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-10n/aelf a249c24424861ac97008afe25eabb78e0c8a5b360f325106b2e81f04bff54e94n/a 
2020-11-08n/aelf 631649fb6ba83e32f7ebfb3b22bbf3e12c338f1daadc91aef6ba98feb805ebdbVirustotal results 34.00% 
2020-11-05n/aelf 2da0acf67c6c589d2b80f2a8c0a9c4e612999d9097900407f8d42b3128216ee0Virustotal results 38.71% 
2020-11-05n/aelf 0ab554cceefe796fd2186a916eb01671c91570da2c57a5ea38807f09d6713ce8n/a 
2020-11-05n/aelf 354a24ec005b0fecdeb2df9b2fabb9aa4d55aaa201899c42fdb222849d650af3n/a 
2020-11-05n/aelf ebe0aacede01d64d686955a20af24c754a47d25556ed0d9eea48ee924ad40ccdn/a 
2020-10-25n/aelf 12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efVirustotal results 67.92%Mirai