URLhaus Database

You are currently viewing the URLhaus database entry for http://104.167.221.114/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3561881
URL: http://104.167.221.114/arm5
URL Status:Offline
Host: 104.167.221.114
Date added:2025-06-13 18:50:22 UTC
Last online:2025-06-21 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-13 18:51:09 UTC to abuse{at}dedioutlet[dot]com)
Takedown time:7 days, 10 hours, 37 minutes Bad (down since 2025-06-21 05:28:09 UTC)
Tags:elf gafgyt link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-18n/aelf 235733c3b02759f01d846d0333b94b3dbf2fee43d843e46f4ce062c30421b606n/aGafgyt
2025-06-16n/aelf e70bcc50967d42e998fda61e96d4b02afcb214db17e187801d6efd6e00ef2654n/aGafgyt
2025-06-15n/aelf a6f6d5e3ebc4717bd0f3de1f7691c3726465976c725319e16e915dda6a6fca15n/aGafgyt
2025-06-13n/aelf 1264a8832da9e1c025dacbea5b61b98c10ae6b19e579b82382469cf57a9a27bcVirustotal results 54.17%Gafgyt