URLhaus Database

You are currently viewing the URLhaus database entry for http://141.98.11.129/gay/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3347286
URL: http://141.98.11.129/gay/arm
URL Status:Offline
Host: 141.98.11.129
Date added:2024-12-13 06:29:05 UTC
Last online:2024-12-16 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: malwarereport
Abuse complaint sent (?): Yes (2024-12-13 06:30:29 UTC to admin{at}serveroffer[dot]lt)
Takedown time:3 days, 16 hours, 26 minutes Bad (down since 2024-12-16 22:57:23 UTC)
Tags:gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-16n/aelf e9a63bdbd303e4f5d91fd6fe0ed094fe87f599d9129d3dc1d4c689259590114en/aMirai
2024-12-16n/aelf 7ed6833683e70d83eb8e210820d25e7b9a22b9ef97aea785ca75c69b1aa70ae1n/aGafgyt
2024-12-15n/aelf 0cabeaadd1acdd37944764604aed632f5d130595366177fd0ed7c0255491d4d4n/aGafgyt
2024-12-13n/aelf bf82b79ca4803adef7ce4d2456d6d3adb04a867fedebd07de87feeb8d5761e11n/aGafgyt