URLhaus Database

You are currently viewing the URLhaus database entry for http://www.secure-network-rebirthltd.ru/x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3379725
URL: http://www.secure-network-rebirthltd.ru/x86_64
URL Status:Offline
Host: www.secure-network-rebirthltd.ru
Date added:2024-12-28 20:10:09 UTC
Last online:2025-02-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-02-01 17:41:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 5 days, 0 hours, 52 minutes Bad (down since 2025-02-01 21:03:32 UTC)
Tags:botnetdomain elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-01n/aelf c47dce8b21525a416dc05409871ec0f374212d05c4abf4858dcc2aea08c52495n/aGafgyt
2025-01-03n/aelf b75eab90673b94fd015bc817741fe37bfaee97166f5430e327c578bd57622349n/aMirai
2025-01-03n/aelf 720f05980490b758b0051ad5ab5170f902863b9658534c3a9a099be6a9828f4an/aMirai
2025-01-03n/aelf ae3c9924b877dcf0937b65fcba781fac86518f884dd6272b4bf537dc54a0c5a8n/aMirai
2024-12-29n/aelf a98c75b7612614ed742dc20e8606ccfbf3e9e420db04a51de199febf79df432aVirustotal results 37.50%Mirai
2024-12-28n/aelf f24f844f1269c757d1f42a3b4ea03675281d7da4a186b851f3c0d149a2488dd5n/aMirai