URLhaus Database

You are currently viewing the URLhaus database entry for http://cnc.mydigitalcloud.ddns.net/bins/dlr.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1453933
URL: http://cnc.mydigitalcloud.ddns.net/bins/dlr.arm7
URL Status:Offline
Host: cnc.mydigitalcloud.ddns.net
Date added:2021-07-14 14:14:04 UTC
Last online:2021-10-27 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-27 18:38:03 UTC to abuse-mail{at}verizonbusiness[dot]com,abuse{at}verizon[dot]net)
Takedown time:3 months, 15 days, 10 hours, 46 minutes Bad (down since 2021-10-28 02:09:08 UTC)
Tags:32 arm elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-05n/aelf 02dfd44046533f02a3a36f681465f721dd5442b9e7153d955b9e0ad7dd7c2a41n/a 
2021-10-03n/aelf 769e325653983114f4f6079de76e44d329d4149a60ef5afa16bd7474a79a7072Virustotal results 36.07% 
2021-07-24n/aelf ead9fc8c5f5e03f318aee3774dde3764b1c6e280891585be9bc0607aaa818c36n/a 
2021-07-17n/aelf fc2aa1d22243d485fbec4b8544882dcdfbbd5086486fa6e8e71d39a19b04eb51n/a 
2021-07-16n/aelf 95fc40c6e3c8e447166d7cb6154f0b47bac4d2a20db3b377609be2e0e6753883Virustotal results 32.79%Mirai
2021-07-14n/aelf 6b78f5c78f2edf24892e9649c4c697d8e7ac7b8081b9efd6ffbe1d41669c9d8an/a 
2021-07-14n/aelf 1ba31deba8fb47f7686944f9c481f91d7563f2668a2ff6f725b928cc25fbd513Virustotal results 27.78%Gafgyt