URLhaus Database

You are currently viewing the URLhaus database entry for http://89.169.35.229/bot.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3579786
URL: http://89.169.35.229/bot.x86_64
URL Status:Offline
Host: 89.169.35.229
Date added:2025-07-09 18:46:08 UTC
Last online:2025-07-13 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-09 18:47:10 UTC to abuse{at}aeza[dot]net)
Takedown time:3 days, 6 hours, 8 minutes Bad (down since 2025-07-13 00:55:59 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-11n/aelf 98a7eb2e67bbd1e85344a525dd1d152aca9ac4c2e3fd0d59b550a61902837022Virustotal results 45.90%
2025-07-11n/aelf 32b898f7ee3404e22791e290729fbce55950aa5a6814de629ee51e5fcbe9e58en/a
2025-07-10n/aelf 1f40a3e910bb4be21a0b0e3ef3435825c70589ffa03d8bc5b67979d1091c559en/a
2025-07-10n/aelf c89aca00a820eaeac5fbd7c45ea3aabb816e1c3d53c41e7eca8e2ff75025d40bVirustotal results 30.77%
2025-07-09n/aelf fcfbe05ee17006d83d212e760eb37b5821e3669823717e97a44705feb83ce597Virustotal results 66.15%Mirai