URLhaus Database

You are currently viewing the URLhaus database entry for http://185.39.207.117/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3502226
URL: http://185.39.207.117/arm5
URL Status:Offline
Host: 185.39.207.117
Date added:2025-04-05 22:28:04 UTC
Last online:2025-04-17 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-04-05 22:29:07 UTC to abuse{at}globconnex[dot]com)
Takedown time:11 days, 9 hours, 34 minutes Bad (down since 2025-04-17 08:03:28 UTC)
Tags:ddos elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf 3a5c86a7631f29a6f599ef74a218dfcc9291aa525cd36fd06d2650364dd1b8d2Virustotal results 41.27%Gafgyt
2025-04-14n/aelf a4c7e43308dacca54cd80d82071cb5a997d5c9198be94d14925389da05d62455Virustotal results 41.27%Gafgyt
2025-04-12n/aelf 73fd00967c1147471e81ae12ef58366ff79ae8afdbb15d2f619af6fe5a454d64n/aGafgyt
2025-04-10n/aelf 63b0fa0da0eea5b58b37afca28c569a72f57d821aae8307838c82403bb3c9f3eVirustotal results 41.27%Mirai
2025-04-09n/aelf 758f5522b7042d4ce37ae6313312771b103331ce25d48d9cd0932d291b3bdb40n/aGafgyt
2025-04-06n/aelf 3b7de09d48ff82ea1e92a3bdc478d34d48d749075abc2dd2470c99e320280171Virustotal results 40.62%Gafgyt
2025-04-06n/aelf 940cb3335364bbfeafe52d914060b07e5a986a1b08592ebc61a7588b89b2729an/aGafgyt
2025-04-05n/aelf 72eb6026c66c96d050f30a3da54cb3c85fad70f9f5b805ea8cf543835ab38dcdVirustotal results 59.38%Gafgyt