URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610348
URL: http://109.205.213.5/resgod.ppc
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-24 04:22:12 UTC
Last online:2025-09-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: redrabytes
Abuse complaint sent (?): Yes (2025-08-24 04:23:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:15 days, 16 hours, 51 minutes Bad (down since 2025-09-08 21:14:32 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-07resgod.ppcelf 79c1d9a2427318b5bfedc8040e8d3bdbd503892b3ad16c641b62886e03efa1f4n/aMirai
2025-09-07resgod.ppcelf f6d512731701decf6d190664168ba078b7fafa2455a0ea8be00d6a94ad1c5b74n/aMirai
2025-09-07resgod.ppcelf 73f89f11300e723cd14089754e90714b2acc3ec072240d8fc3a03e3041f896b1n/aMirai
2025-09-06resgod.ppcelf 3545b21c73cfd28a4ca2b5fd5c654bf8f9a68d8eacbb36786bffe5635fe3b0a4Virustotal results 37.50%Mirai
2025-08-26resgod.ppcelf b3f0efadb786b232cbca56a9bf5de3af8dd7beadb24e35aff846afe611279af8n/aMirai
2025-08-24resgod.ppcelf d4b30e4f367331a4b3713ab0416042c28786df4a03b0e44c45d732b8ace37265n/aMirai
2025-08-24resgod.ppcelf e486a6860fcb52ef37d48811497e8d711911ba30240fa83aa8e63f86980c6999n/aMirai
2025-08-24resgod.ppcelf b21b51c6f5f99188d65c277375bd5d2e943b22a332a0cd1cbda46d9a2929c67en/aMirai