URLhaus Database

You are currently viewing the URLhaus database entry for http://byte-main-cnc.n-e.kr/dlr/dlr.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3286329
URL: http://byte-main-cnc.n-e.kr/dlr/dlr.x86
URL Status:Offline
Host: byte-main-cnc.n-e.kr
Date added:2024-11-11 11:29:05 UTC
Last online:2024-12-02 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-11-27 07:54:08 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:22 days, 23 hours, 39 minutes Bad (down since 2024-12-04 11:10:06 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-27n/aelf e5ae9174750f98d80875c0e51ae0623d14fb1db7bf136eeafd515dd391e4b553n/aMirai
2024-11-26n/aelf c8719f411ca7e0b482c1992394f2b91f2fa40f084cb66b07d3a72dc03bc78e18n/aMirai
2024-11-21n/aelf f81c1a9018bca07ab3abe4f075df2b6b1d175c8162f3586fd69d3f15d49d032fn/aMirai
2024-11-14n/aelf 180632c85d78d71b08d1695d1e335077a987a8cccae000624a5103f83390aa37Virustotal results 25.93%Mirai
2024-11-13n/aelf 15b3e328e2acfec9448146bf0b326bd4bee12c38eda5d533c2e25cb4bd9f0d8cn/aMirai
2024-11-11n/aelf a93ea3bd1c97ecba63c0697f6fa2fd84ba1f7fbae6108a623355ee0193b32425Virustotal results 58.46%Mirai