URLhaus Database

You are currently viewing the URLhaus database entry for http://selfrep.carteldesinaloa.ru/389242390482/nuklear.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3277463
URL: http://selfrep.carteldesinaloa.ru/389242390482/nuklear.arm7
URL Status:Offline
Host: selfrep.carteldesinaloa.ru
Date added:2024-11-05 19:16:07 UTC
Last online:2024-11-14 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-11-05 19:17:08 UTC to abuse{at}virtualine[dot]org)
Takedown time:8 days, 15 hours, 12 minutes Bad (down since 2024-11-14 10:29:17 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-07n/aelf 665479c45de45cd8b54eb6bb099764de5e1f689609a27660c026fbf097ef6325n/aMirai
2024-11-07n/aelf 834ffbe44772c6acb3ae3abedee68decb8ba3c848f9889b1245161c05dcb23dcn/aMirai
2024-11-06n/aelf 01a8bdaed1410bb3e65089d036943a747ebb1325f61d3b14d01bd5649485e82dVirustotal results 57.14%Mirai
2024-11-06n/aelf 5ababfb717882367642d69cb70846a1e319becde91c6599b19d63c748a282f01n/aMirai
2024-11-06n/aelf f704f0361167c3aeb5a3eee160c10b727f363bf93f305150a033a4ffbda6d799Virustotal results 60.94%Mirai
2024-11-05n/aelf 86f805ee775d9f5f80e9cab67410afbc986c012233258567a60e1c546f662280Virustotal results 60.32%Mirai
2024-11-05n/aelf da00c1948fed96275fb4d150db15cf050b817aeb3d8fded35d03349c9fdf0c89Virustotal results 60.94%Mirai