URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.169/armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3579950
URL: http://213.232.114.169/armv4l
URL Status:Offline
Host: 213.232.114.169
Date added:2025-07-10 00:33:12 UTC
Last online:2025-08-08 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-10 00:34:12 UTC to report-abuse+xtom{at}virmach[dot]com)
Takedown time:29 days, 17 hours, 49 minutes Bad (down since 2025-08-08 18:23:50 UTC)
Tags:elf gafgyt link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-14n/aelf f9c0cd0ddb36a527080de2f95bf6f707f6a9fe210573aec3f89d0168a7b651f9n/aGafgyt
2025-07-13n/aelf 8bfcfbe37774b9c8220763d9d218f27c8af321c4d495c24c23b37ec72b0e90cfn/aGafgyt
2025-07-11n/aelf 1cc2326eae57eac9a023616669053b5bea6d471146fb9b8463d8bff9831cff4cn/aGafgyt
2025-07-10n/aelf 2400866fd54e271bafb64861fc7957ba9c878b89d005a918f2c87370c7116b76n/aGafgyt