URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/armv7l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569510
URL: http://158.51.126.131/armv7l
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-23 10:32:06 UTC
Last online:2025-08-23 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-23 10:33:11 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 0 days, 14 hours, 48 minutes Bad (down since 2025-08-23 01:21:14 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-04n/aelf 69c12ce6f569adfaa217f1ebd365b727e3d2f882f22ef10169c8dc7ad3a05f4eVirustotal results 59.68%Mirai
2025-07-07n/aelf 9b6e6be673ec666e4b81c77314c456309e492b6a32b54589690d8366dd0b5993n/aGafgyt
2025-07-05n/aelf 3abedf3fd4e0f773c975a9c87d654080a52322db8f2d2147c1ee5da987be6a71n/aGafgyt
2025-07-05n/aelf 519896caff698eff96be73e410e84fa7f014bfccf02177521c66c7f4398f4be0n/aMirai
2025-07-04n/aelf a1f1d4f5bcb88eb39600ec24d6e861ddfb8a2bf2a76836036e10847330346c1fn/aGafgyt
2025-06-26n/aelf 1698eab2a389a4df2f3ec7970a9f2179b6cd38ff73b26887229980a6650d9ec7n/aMirai
2025-06-23n/aelf 387fc64fd24a9422d29a76ca190ef3ea3faf8b4b1ffcaebf457b663d482bde80Virustotal results 14.06%Mirai