URLhaus Database

You are currently viewing the URLhaus database entry for http://spotslfy.com/.Sarm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2809498
URL: http://spotslfy.com/.Sarm5
URL Status:Offline
Host: spotslfy.com
Date added:2024-04-11 21:03:12 UTC
Last online:2024-04-29 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2024-04-29 02:08:06 UTC to abuse{at}v-sys[dot]org)
Takedown time:18 days, 11 hours, 41 minutes Bad (down since 2024-04-30 08:46:02 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-30n/aelf fb088cec2214538871e219a8f90f737cbdb9b759d2473d92efe9de084fbc9e30Virustotal results 58.73% 
2024-04-16n/aelf 451171bbeb2d53d419b38803f1fd7b58c04476dbfd3a5d5a598373c03250528an/aGafgyt
2024-04-11n/aelf 4aa603f940c0c44357cd9eec57d6eb93cef87d921da0c0aeeaf47cf9293f72f0n/aMirai