URLhaus Database

You are currently viewing the URLhaus database entry for http://141.98.11.129/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3346990
URL: http://141.98.11.129/arm
URL Status:Offline
Host: 141.98.11.129
Date added:2024-12-13 00:47:07 UTC
Last online:2024-12-16 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-12-13 00:48:11 UTC to admin{at}serveroffer[dot]lt)
Takedown time:3 days, 20 hours, 52 minutes Bad (down since 2024-12-16 21:41:08 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-16n/aelf e9a63bdbd303e4f5d91fd6fe0ed094fe87f599d9129d3dc1d4c689259590114en/aMirai
2024-12-16n/aelf bb0dea7492507c4304d39060c35d89942cfbc2b1a7bd8ea21ff59cc1fef5e327n/aMirai
2024-12-15n/aelf 0cabeaadd1acdd37944764604aed632f5d130595366177fd0ed7c0255491d4d4n/aGafgyt
2024-12-15n/aelf e353a727a93954a4fb649d4a93b34b4f359d5fc884a0da7989b21b622e6f1c92n/aGafgyt
2024-12-14n/aelf bf82b79ca4803adef7ce4d2456d6d3adb04a867fedebd07de87feeb8d5761e11Virustotal results 41.38%Gafgyt
2024-12-13n/aelf 36b5ad3793ba15e920ea49a43467610bfce85149afc12af166a56bb2011a9165Virustotal results 58.06%Mirai