URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/t/armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3592571
URL: http://158.51.126.131/t/armv4l
URL Status:Offline
Host: 158.51.126.131
Date added:2025-07-29 07:25:09 UTC
Last online:2025-09-07 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-29 07:26:16 UTC to abuse{at}hostodo[dot]com)
Takedown time:1 month, 9 days, 19 hours, 21 minutes Bad (down since 2025-09-07 02:47:37 UTC)
Tags:elf gafgyt link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-31n/aelf 51dbfe5eb3331858e57320a5a2327599fc51d18bab6c76c5d7cb03ca4621078bn/aGafgyt
2025-08-23n/aelf 9b8a4f2f10f8e7c07bb98f6e195a74b42fbaedd20c1a81c9a3eb21ef9774a66bn/aGafgyt
2025-07-29n/aelf 5d4f48b7ef91352ae43d6719798c4ce2727ea3ebfcc19997a9a0940217627344Virustotal results 57.81%Gafgyt