URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610357
URL: http://109.205.213.5/resgod.mips
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-24 04:22:18 UTC
Last online:2025-09-09 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: redrabytes
Abuse complaint sent (?): Yes (2025-08-24 04:23:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:15 days, 22 hours, 9 minutes Bad (down since 2025-09-09 02:32:59 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-07resgod.mipself a829c07ba77c4fa8e2153e65e68b14ffa0fe8bfb5da8b0643ecd43ad63f20506n/aMirai
2025-09-07resgod.mipself 1fa8d201008662a10649b5eab3448da91b5bb37cbc789f6108ea91cfc6864659n/aMirai
2025-09-06resgod.mipself c6498528e71b1d1bf3b04ab8f92d810c081180c19672d40a70c75beb0b53e8e2Virustotal results 37.50%Mirai
2025-08-26resgod.mipself e835b89aa1f95af1187d308b10555035f7f6fb97b6782d0f611a957720647ea0n/aMirai
2025-08-24resgod.mipself d29dccab4b0c5597d8d70efc60a3e14e6868a2175b6366a0f8ccfe0a790d65cen/aMirai
2025-08-24resgod.mipself 0502879b7c0df72bc5d892e0fba94f907637ddef67be4369e115fdf718e90e52n/aMirai
2025-08-24resgod.mipself b4d20e02802148e43640880ebf6bf4a703bfa06d4fbbca5da01c127b1c0a3354n/aMirai