URLhaus Database

You are currently viewing the URLhaus database entry for http://141.98.11.129/gay/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3347288
URL: http://141.98.11.129/gay/arm5
URL Status:Offline
Host: 141.98.11.129
Date added:2024-12-13 06:29:05 UTC
Last online:2024-12-16 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: malwarereport
Abuse complaint sent (?): Yes (2024-12-13 06:30:29 UTC to admin{at}serveroffer[dot]lt)
Takedown time:3 days, 14 hours, 38 minutes Bad (down since 2024-12-16 21:08:53 UTC)
Tags:gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-16n/aelf 54487b2d61682a2967e6a3d8761c09d2db8cc4157a826dc7f197e44e87b1b994n/aMirai
2024-12-16n/aelf 016558ed4fc359aa976ddaa8422d1850125737514a4373ea9a5e9aa2d4f60306Virustotal results 22.22%Gafgyt
2024-12-15n/aelf 52f5cec403912d29bbfe7daa6b10576f26e9fb7e3aa110e749e60d0b92fff59cn/aMirai
2024-12-15n/aelf 8e06061f64c3fd05528d5a6fae6ae3a925a6f3c1658b74a519588069fc82eb9dn/aMirai
2024-12-13n/aelf aa712c166dbefaf7c84f1c679b71fe37eaf35d7aea8d3fca339613d67df48e70n/aGafgyt