URLhaus Database

You are currently viewing the URLhaus database entry for http://91.80.138.168:44081/Mozi.m which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:932579
URL: http://91.80.138.168:44081/Mozi.m
URL Status:Offline
Host: 91.80.138.168
Date added:2020-12-20 10:36:10 UTC
Last online:2020-12-20 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: lrz_urlhaus
Abuse complaint sent (?): Yes (2020-12-20 10:38:08 UTC to italy[dot]abuse{at}mail[dot]vodafone[dot]it)
Takedown time:2 hours, 7 minutes Good (down since 2020-12-20 12:45:17 UTC)
Tags:elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-20n/aelf 161b5f34ff48e513e68938cf4577ae0abc68aa956fff833c32784d47be420b9bVirustotal results 46.03% 
2020-12-20n/aelf a829073855f00e14a923e74523d0e69d5cd99ad976ac4f23a71fb4e8fd5640fcVirustotal results 30.19% 
2020-12-20n/aelf 585e4f8d76f06bedeb3bf65b6ea1e199d12eaf6936c4231396096cd4dc77d15dVirustotal results 25.86% 
2020-12-20n/aelf c186c0b876a56d0da7b79bc2cae2e2ecf4617518fd9c996568da100e99179693Virustotal results 31.75% 
2020-12-20n/aelf 12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efVirustotal results 69.35%Mirai