URLhaus Database

You are currently viewing the URLhaus database entry for http://bp.somersaultcloud.xyz/cundi.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2759519
URL: http://bp.somersaultcloud.xyz/cundi.arm7
URL Status:Offline
Host: bp.somersaultcloud.xyz
Date added:2024-02-11 08:28:08 UTC
Last online:2024-02-23 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-02-11 08:29:08 UTC to abuse{at}cdn77[dot]com)
Takedown time:11 days, 22 hours, 17 minutes Bad (down since 2024-02-23 06:47:05 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-23n/aelf efbed4bf201d4597a622a83a9fc19128508ea5c8232051eb3e9885bae88550a1n/a 
2024-02-22n/aelf a9ebda82a954542bb402dd80ef2a23f551aa54486668d639e6ab50fe1e69e722n/a 
2024-02-22n/aelf 8361555e6e6616b5f67651c8a0ab31249074796a82e25147d85bac19cf599b3fn/a 
2024-02-22n/aelf 45fbcebf6970c7291242f3a4c82dddb99952634fa0497804f80648ab73e240a2n/a 
2024-02-22n/aelf 0c95aeb6fc9eb6c029bb7ad589217d9a68b9e917012da2d0be7a3a77cddd4908n/a 
2024-02-19n/aelf 53140cc694886900eee47745f8cd20c85323120a7fd545920b75eb96b959b6ceVirustotal results 45.16% 
2024-02-11n/aelf 8308cf48f9c89479d4b0b03b7b6ec26d487bfffa7e85a2baf9e3a5f3a8cf283cn/a 
2024-02-11n/aelf 172ecd2ed9f56c27d915edda6dffebda627b2f7de3ed79254e06a9e5da3b8567n/aMirai