URLhaus Database

You are currently viewing the URLhaus database entry for http://178.215.238.13/g/bin.armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3239784
URL: http://178.215.238.13/g/bin.armv4l
URL Status:Offline
Host: 178.215.238.13
Date added:2024-10-17 17:31:07 UTC
Last online:2024-10-30 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-10-17 17:32:11 UTC to dc{at}perfectonetworks[dot]com)
Takedown time:12 days, 7 hours, 48 minutes Bad (down since 2024-10-30 01:21:07 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-20n/aelf a6c180dcf84d244bbb97ad591244266290d1d8de8653178f91d40d0f0a85a424n/aMirai
2024-10-20n/aelf d14e7c725624442093564eb6b96cc8a1dcd020e3cba979be6ecc62e8b8483785n/aGafgyt
2024-10-20n/aelf d466c8e6cd43112bf258a419395af971d145a66f8b7b47be64e7f40ead42fd6an/aGafgyt
2024-10-17n/aelf b5cd78422c3fa7a9ca9e93bf15a52b477b6d15ffd502e881eee6601c172b9a0cn/aMirai