URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569521
URL: http://158.51.126.131/armv4l
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-23 10:36:06 UTC
Last online:2025-08-23 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-23 10:37:11 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 0 days, 15 hours, 15 minutes Bad (down since 2025-08-23 01:52:57 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-04n/aelf 2171bb00f0826c172cdca83d441183c74084b65d8a78e10e1482c445f060205bVirustotal results 51.56%Mirai
2025-07-07n/aelf 80d017844c16ccbc0d1206aaf20452c3c8ea1b3063eb9ab7954b28aa063ac858n/aGafgyt
2025-07-05n/aelf de81886ede422286ad57c5fc8a2a57593c2a048f9ad92a17592d56b19e16e3a8n/aGafgyt
2025-07-05n/aelf 6731edbdc7f3f8daeaeeb60305f250f876bfe725b2947073f9de6edcdf0287d1n/aGafgyt
2025-07-04n/aelf 896c087893cc6795cb091434db436f7a45d9b8faf895fbacb4f75015803f47d9n/aGafgyt
2025-06-26n/aelf d03eff3c397574df0af35396bc2c1bd1f53e87a1160683de66e9e9a41fce52efn/aMirai
2025-06-26n/aelf e06733f55074f9ef3c484d507ebb9c54a961cdd19960967834fb62080997f0cen/aMirai
2025-06-23n/aelf 7a5a5c813d636d96906fb4bf8f76c7f296a467dca756e92450f32dc69d781b71n/aMirai