URLhaus Database

You are currently viewing the URLhaus database entry for http://byte-main-cnc.n-e.kr/dlr/dlr.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3286326
URL: http://byte-main-cnc.n-e.kr/dlr/dlr.mips
URL Status:Offline
Host: byte-main-cnc.n-e.kr
Date added:2024-11-11 11:28:06 UTC
Last online:2024-11-28 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-11-27 10:31:22 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:22 days, 23 hours, 41 minutes Bad (down since 2024-12-04 11:10:46 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-27n/aelf 98873d82a2a012d3257979a8e517e96dd19176b6c2e32b3c6e288313ba93779fn/aMirai
2024-11-26n/aelf 252af59966d1fd58a94b6397f02e04ce785da3050e3e7e573fcbfcad2c797203n/aMirai
2024-11-21n/aelf 4c19903bd3f5235ca4f8b7184199aa2df220019008c4e9c6802ad19339d2beefn/aMirai
2024-11-14n/aelf 412661a317a946a2aca23d7ac4ae9c0bdca63d843dbc5d126b79afb9c56426fan/aMirai
2024-11-13n/aelf 7387bdd216fb5604f8478cf0203ee0f8f4aa4efa1e69ddc703768a19dc6452ebn/aMirai
2024-11-11n/aelf 6b63e93361d06598e51c164f0e8feb8514e86f592f8b029afc45d3cb8e29d7a1Virustotal results 57.81%Mirai