URLhaus Database

You are currently viewing the URLhaus database entry for http://92.113.21.114:81/armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3593719
URL: http://92.113.21.114:81/armv4l
URL Status:Offline
Host: 92.113.21.114
Date added:2025-07-31 15:13:08 UTC
Last online:2025-08-11 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-31 15:14:16 UTC to abuse{at}hostinger[dot]com)
Takedown time:10 days, 20 hours, 42 minutes Bad (down since 2025-08-11 11:56:30 UTC)
Tags:gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-11n/aelf 1b0f14fbdf7b6c35a1a20c54cb63bce4b4a872bb21928ea8fc591c71f374ba7bn/aMirai
2025-08-10n/aelf 5ad2f330adc43117af5dba048185f94ebae7f4a49c89c04cb7263ec048534fecn/aMirai
2025-08-09n/aelf b5c07f28a26f5424f6f07a6dbd48fe3a45db5aafb67bb5b4268b7f3a415c89bfn/aMirai
2025-08-09n/aelf 4eaaa7f6cc22ce6a200cae63cd567c4bd6f38010d4815e1f1ac251a132c3bef8n/aMirai
2025-08-06n/aelf 22e14cf2650ea7d3999c8ec001367150beef1888863370318e00b5309a330fa7n/aMirai
2025-08-04n/aelf 025500dca4712e910aaa14b16441c256899ad65601eff946131e7f455e5fb28fVirustotal results 40.62%Gafgyt
2025-08-02n/aelf f7e333174a955bf8d31ce27b45964dcc714bdc2f0761a207e764299c246e9ed8n/aMirai
2025-08-02n/aelf 211a91ff829527ea792318fee71757b1517aa0ca237bf495f3c7b58b2ac0b503n/aMirai
2025-08-01n/aelf 574d4f386ed6d922f8ec6916ec082515c0e128ca096d692d62acfd312e342479n/aMirai
2025-07-31n/aelf 799dcea8f3e4217a277e94f3d8581c098c990731b5fb6ec4c9c473b9934ce97cn/aGafgyt