URLhaus Database

You are currently viewing the URLhaus database entry for http://o0s.cc/tt/armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3350369
URL: http://o0s.cc/tt/armv6l
URL Status:Offline
Host: o0s.cc
Date added:2024-12-15 13:35:17 UTC
Last online:2024-12-25 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-25 13:21:12 UTC to abuse{at}ghostnet[dot]de)
Takedown time:10 days, 2 hours, 49 minutes Bad (down since 2024-12-25 16:25:42 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-25n/aelf fb4215132aee270148aabc85c0d6272b828cb5cf035c6b8823638c03a99c3e16Virustotal results 50.82%Gafgyt
2024-12-25n/aelf 5edf1214e4349a99a17c1a132b9343397eb4b808f9b63685dd3a650af055ceb1n/aMirai
2024-12-24n/aelf 7ece6b3ea0def41175f59467cc817611f815b1d9997a496435dca089243e2c0en/aGafgyt
2024-12-23n/aelf 4ecbb0274d849f0234b05e8e2ea4d694ce4c383c086f380f894b09ada9e5371dn/aMirai
2024-12-15n/aelf bcbc40348338519f815a6aa2c3160ade4d1d5d3566ee98a1093ab187333d058eVirustotal results 59.65%Mirai