URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.169/armv5l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3579953
URL: http://213.232.114.169/armv5l
URL Status:Offline
Host: 213.232.114.169
Date added:2025-07-10 00:33:12 UTC
Last online:2025-08-08 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-10 00:34:12 UTC to report-abuse+xtom{at}virmach[dot]com)
Takedown time:29 days, 17 hours, 1 minutes Bad (down since 2025-08-08 17:35:51 UTC)
Tags:elf gafgyt link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-14n/aelf 04e4727b0fe9af4c94417df2482a6463f2d80dcc6c116cf055c5f29d692d401an/aGafgyt
2025-07-13n/aelf 063a9e7683d60da11dc16038293f7186e726dbc7901ac56ab26344db89f585ebn/aGafgyt
2025-07-11n/aelf 40c2ddf82d6971e342c1fe50767ad660ee38880001d13e6d44a67c00cca2b21en/aGafgyt
2025-07-10n/aelf b774cc60530608702624a53f75e5697c4c8df48a8e7922400626f51c5d509853n/aGafgyt