URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/armv5l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569507
URL: http://158.51.126.131/armv5l
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-23 10:32:06 UTC
Last online:2025-08-23 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-23 10:33:11 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 0 days, 15 hours, 20 minutes Bad (down since 2025-08-23 01:54:07 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-04n/aelf 506a3e39a46d0e6d13ba89dd5a6fe2aa81c5122db15742d4ce509a3c0738ff01Virustotal results 59.38%Mirai
2025-07-07n/aelf 25eb923bae5899e65e48927d510b90fa5e76c9d4256e0dccbb344032df710616n/aGafgyt
2025-07-05n/aelf 98f4113c3b8820aaf1e6f47bf110e505729f6e97e184ed79498b6625611383c2n/aGafgyt
2025-07-05n/aelf a3563979135d410bc514a86a37ff4ea60818b4bc962e07c516adbd988aad35f1n/aGafgyt
2025-07-04n/aelf b5aa16f2db4d9ab91b3797da07038b5204ce1c6df5b22ca7db0cf52fe4e396e6n/aGafgyt
2025-06-26n/aelf 5a3050b4eb9af2332758755fb56bdbbd91888943b3ad901ae87e900746f4da2cn/aMirai
2025-06-23n/aelf ee2120946ac5ee74090a094d9d409e22f994ce64e8f6661e2b17b9f11ff990fdVirustotal results 14.29%Mirai