URLhaus Database

You are currently viewing the URLhaus database entry for http://42.112.26.36/l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469426
URL: http://42.112.26.36/l
URL Status:Offline
Host: 42.112.26.36
Date added:2025-03-06 13:27:03 UTC
Last online:2025-03-21 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 17:54:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:14 days, 9 hours, 46 minutes Bad (down since 2025-03-21 03:40:35 UTC)
Tags:gafgyt link mirai link sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-19n/ash b54d09f81cddc9f71f05ed4ac144279126025b66baf4e626d417f4ac36a1c441n/aGafgyt
2025-03-17n/ash ccb8700d1da90ccbedc2a3826c7b51fa4af9b36e1c426aa7e0a137ae7aad60cen/a
2025-03-17n/ash 03a164ea27d728588d84a1f483d40a2453e1557c03b3ad83ad7c5de85cd98fe2n/aMirai
2025-03-12n/ash daa9bdbfe7472cea95e506af7fbdc5484ed12be674136b6c24353efea06799e5n/aMirai
2025-03-06n/ash 8be3c7a7516884ee15d6263ee5bac6cdf54551173619d46693da8b77a052b540Virustotal results 49.18%Mirai