URLhaus Database

You are currently viewing the URLhaus database entry for http://ptptonuwu.duckdns.org/bins/xnxnxnxnxnxnxnxnmipsxnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3696649
URL: http://ptptonuwu.duckdns.org/bins/xnxnxnxnxnxnxnxnmipsxnxn
URL Status:Offline
Host: ptptonuwu.duckdns.org
Date added:2025-11-05 03:54:13 UTC
Last online:2025-11-16 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-15 13:55:15 UTC to abuse{at}virtualine[dot]org)
Takedown time:11 days, 2 hours, 14 minutes Bad (down since 2025-11-16 06:09:43 UTC)
Tags:botnetdomain elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-15n/aelf b45801d1c9bb5d31913f3c6d1bd83db4412014dd13b9f2e81719422e1d1b9ec1n/aMirai
2025-11-12n/aelf cbada6601d85cec73726566a544b3a9d9ad619d7b8c768123737115bbddf8afcn/aMirai
2025-11-05n/aelf 23e8188ff6a5422aa9a12a008406d166d10ceb6f5db08183acbd65a6898d3e7eVirustotal results 17.19%Mirai