URLhaus Database

You are currently viewing the URLhaus database entry for http://vbtgsze.r-e.kr/bins/byte.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3377108
URL: http://vbtgsze.r-e.kr/bins/byte.x86
URL Status:Offline
Host: vbtgsze.r-e.kr
Date added:2024-12-26 10:00:11 UTC
Last online:2025-01-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-30 18:16:14 UTC to abuse{at}proton66[dot]ru)
Takedown time:20 days, 23 hours, 34 minutes Bad (down since 2025-01-16 09:35:26 UTC)
Tags:botnetdomain elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-16n/aelf eea347168b8f25340b94765571a0d5906da3f67210d78f350421976e7a703e8fVirustotal results 67.19%Mirai
2025-01-16n/aelf 17529ec36be870b9c139f4c7a5d09ce2b8a8c213423f5a28dbc830c7580af4a4Virustotal results 65.62%Mirai
2025-01-13n/aelf 898aabc9633231e530c8a5ce539c80b11535aacbc9f28740cf42016eee0fc787n/aMirai
2024-12-28n/aelf 9928c99ec2ef2eee7df7c786dbc35f5b765e9701de45e194ab59123bdf535983Virustotal results 66.67%Mirai
2024-12-26n/aelf 3c0eb5de2946c558159a6b6a656d463febee037c17a1f605330e601cfcd39615Virustotal results 63.49%Mirai
2024-12-26n/aelf 5eacaa1cdd540e88cd6cc9e21f1d00af5aa564821103806302b98fe132e7855eVirustotal results 39.34%Mirai