URLhaus Database

You are currently viewing the URLhaus database entry for http://103.176.20.59/garm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3591783
URL: http://103.176.20.59/garm7
URL Status:Offline
Host: 103.176.20.59
Date added:2025-07-28 20:14:12 UTC
Last online:2025-08-25 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-07-28 20:15:12 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:27 days, 23 hours, 41 minutes Bad (down since 2025-08-25 19:56:57 UTC)
Tags:censys elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-22n/aelf eedbf38d0dd89966b59f61efb9da1ef4c369c4c693b71481e0382843d6f92e85Virustotal results 20.31%Mirai
2025-08-21n/aelf f108c3c1634b29ef5555df8364156c1583ccced2e5276d00a5140f7af98cd932n/aGafgyt
2025-08-15n/aelf adca68ce47eb91b96a0394cffcc996fd98cf2f5caa339eb65f383ced50bc6d33Virustotal results 18.75%Gafgyt
2025-08-09n/aelf 499ac8f975c690d6e7dd1d8ba994416501162a919e7bdb5e1fd7fb1717cba069n/aGafgyt
2025-08-05n/aelf 5b6616a981e56b45c51ae7539df6439f1a078ee9eb173d4ae03159e7eb4abc54n/aGafgyt
2025-07-28n/aelf dd19e59205da37c4d337766e42e4cc920dcca8ab1807ccbe760844ea2d37dc6bVirustotal results 54.69%Gafgyt