URLhaus Database

You are currently viewing the URLhaus database entry for http://botnet.nguyennghi.info/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2557040
URL: http://botnet.nguyennghi.info/arm5
URL Status:Offline
Host: botnet.nguyennghi.info
Date added:2023-03-03 20:00:33 UTC
Last online:2023-10-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: tolisec
Abuse complaint sent (?): Yes (2023-09-02 05:18:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:7 months, 3 days, 23 hours, 35 minutes Bad (down since 2023-10-03 19:36:17 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-02n/aelf eb37f0a67e1b77d1117fa8dafaef93a31de6dcb72bdfb36bb8c9a803cb502323n/a 
2023-08-15n/aelf 10a9332cf842efe32465258e99bac7e64ce7081b50143d1f60c112f926b70eacn/a 
2023-07-26n/aelf a579aa9c598ac83cbffcc61ad72a7eed026a7345d2acc1b3dbb71f749643f793n/aMirai
2023-07-07n/aelf 04e0cd05be97ee135f0d028bf033d428ebb8ed4906d180eabc4cad3e703672fdn/a 
2023-07-01n/aelf cc403ea29c2b10d543a5c610b3cd896ce19f31c2f5bb232f2c2033e1b9368ed1n/a 
2023-06-08n/aelf fbcec53dadc81cfa89ef88b87ec8224ba3e17ce61d6c4253898392f055798bf6n/a 
2023-06-04n/aelf 7e7cf01fcdd47552a9fc57466ce043d596dd7334aec3c3fd9ebce1c9f59b42ben/a 
2023-05-15n/aelf 9e14382c70f44bfe4472cf674b19f0d171a30728c37c503940ebac0b3bcd7477n/a 
2023-05-09n/aelf 339d67c5cf76ec68d1547fa6bb43c2cc9cf570259886b9f9f410e7aedf89ebd8n/a 
2023-04-27n/aelf dc9daebcb2a7d50e304919352cc03e50d9e371b0d620e490df61d0d811cec675n/a 
2023-04-22n/aelf c4bf0a5a8dfef0578689300246578fa97b27e958661cf678c9c2ca17b7db2b6cn/a 
2023-04-12n/aelf 408235b8dee71c723e6fcffaafc725fcb2eb233a17222f0ca3b3f42a75033addn/a 
2023-03-19n/aelf 826ff6907778a47aad222b4525687adc3fdfb99e9cd4bbac8a65254be47e69f3Virustotal results 59.02%Mirai
2023-03-13n/aelf f00d0189a3c0f55ca2830d909eb7265430b5688e2a0419969023a40c423df70cVirustotal results 67.21%Mirai
2023-03-03n/aelf 4374fe1614dd01cd0390a754468ada3ed1df9225b950c7e86f230cd693890910n/aMirai