URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/narmv7l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3562843
URL: http://158.51.126.131/narmv7l
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-17 05:21:09 UTC
Last online:2025-09-07 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: vanilla
Abuse complaint sent (?): Yes (2025-06-17 05:22:12 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 21 days, 21 hours, 39 minutes Bad (down since 2025-09-07 03:02:04 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-02n/aelf 89e53d182f78499c985edf7e16c4da4d768b090fe685d92f5b7778ff2748f975Virustotal results 42.19%Gafgyt
2025-08-31n/aelf 3200fbbee76b80d6a02d7c8372aa1ee27d53b5ba6dc536ab0daf4aec88b51661n/aGafgyt
2025-08-23n/aelf 762b8b4b4fcb47108b0b698149cd8860e1fb5878e90cbc03c5f32d7831c94b29n/aGafgyt
2025-07-14n/aelf af4eca4d83eb65a910d15b050384a943f7180428a8f4f67d1ee10555d4b700b1n/aGafgyt
2025-07-09n/aelf fdecc2d6d355f37cc0a9290541d0a05b91c0b6cf3a5d4f8bbfffe33eb834f3cfn/aGafgyt
2025-07-09n/aelf 3cc666ac51bf7057c69bbb520b4557067db72c590412a1cfe21499d594c7fdb3n/aGafgyt
2025-07-05n/aelf 1b8bafe7bc73b2709b485e2273af4d8595700ab02f637e52b9cc1bbb380bdb9cn/aGafgyt
2025-07-05n/aelf e1df9766ddb3da7b05a93f1b8fdfc3e3b7870a856c919c452df3a1c8a6aa5d1en/aGafgyt
2025-06-26n/aelf d34d674663b3ebfb5a57c65eb73a5660a4ce2ee422e7a38a6b4d71a35925694en/aMirai
2025-06-17n/aelf 0d9a15bbd4f7f767e7c3a1b3582a4ffd2d945738a9621775e40a61bfc2df8b9fVirustotal results 35.56%