URLhaus Database

You are currently viewing the URLhaus database entry for http://103.176.20.59/toto which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3591802
URL: http://103.176.20.59/toto
URL Status:Offline
Host: 103.176.20.59
Date added:2025-07-28 20:15:23 UTC
Last online:2025-09-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-07-28 20:16:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 29 days, 10 hours, 48 minutes Bad (down since 2025-09-26 07:04:35 UTC)
Tags:censys gafgyt link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-24totosh 1dcfdc66d7b9e8c145d3b057d4a1dde532b681bd4a2d125d45f4942538548e7cn/aGafgyt
2025-08-21totosh 60b54a5b9b5904072dedee9a283e7f27e473d54703253bd9eb7b1c0dc938093dn/aGafgyt
2025-08-20totosh b44df798d6d8eb235baefc57f36104823d25f8fa97c97110224323b67b137103n/aGafgyt
2025-07-28totosh 1eb2d667642518243b790f55f61971ad769cad620f434bb8320d62118415d79fn/aGafgyt