URLhaus Database

You are currently viewing the URLhaus database entry for http://bayerngrow.com/rep.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3423358
URL: http://bayerngrow.com/rep.x86_64
URL Status:Offline
Host: bayerngrow.com
Date added:2025-02-01 19:30:07 UTC
Last online:2025-04-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-04-14 23:40:07 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 months, 7 days, 14 hours, 42 minutes Bad (down since 2025-05-10 10:14:01 UTC)
Tags:botnetdomain elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-09n/aelf 1b37463f1e00dbc7fe61f828d1390edd0eb3821cfe644e19509e2ffca3a1f4c1Virustotal results 53.97%Mirai
2025-04-17n/aelf 88de6169c2d460109e4e88802ce6aa1e53f4f39c8710eae51593ae36c8485e6an/aMirai
2025-04-14n/aelf 9a7217d42f0a8c769635a2243cd931ff2742d0e06f9204a8244b3922ff2b84adVirustotal results 21.88%Mirai
2025-02-01n/aelf 2e82e8d271a19c6c2429c420b6a8d5d5c25bebf27e29d82c94ef0e85c9e904feVirustotal results 20.31%Mirai