URLhaus Database

You are currently viewing the URLhaus database entry for http://teamc2.duckdns.org/bins/powerpc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3722802
URL: http://teamc2.duckdns.org/bins/powerpc
URL Status:flame Online (spreading malware for 24 days, 19 hours, 1 minutes)
Host: teamc2.duckdns.org
Date added:2025-12-02 05:05:16 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-02 05:06:17 UTC to report{at}abuseradar[dot]com)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-26n/aelf a75d6a326576493d9a8fbc640f844428e88b30c2d000c216e6b22e1e5b32fbd5n/aMirai
2025-12-26n/aelf 5f66bb05b7b4f81ba7ccf5b8f154ab3b970372b0020952b840c6d295f32936ean/aMirai
2025-12-26n/aelf 78ed2eed2218c91258488eea7377a0ceec4913447c62f0a81310b390a3b49ed2n/aMirai
2025-12-15n/aelf 7f74c7a5d906226e79693c0a547871d1693e84a148cb8a0571b7b838ef96d57an/aMirai
2025-12-14n/aelf e2b95f3515821b538f6b321b43931e36d794230e760a0456e31e18e333b62fe1n/aMirai
2025-12-13n/aelf 179c751dd3a6c608622f7217a5c3451a0a52a265176f545431cd6f165d253324n/aMirai
2025-12-13n/aelf 66e13f05747c74cddb2760d70d4a690a30c1a1edbcb610e7f4947b0c28a7680en/aMirai
2025-12-04n/aelf e2bbaa1ecea9fe9b9b78387a10e2ed8b87608cce565cd4c0cc509dcbaae48bf2Virustotal results 51.56%Mirai
2025-12-02n/aelf 6b2c6b76e0d75e311c9f2c94d197c9f7cb3a7dd15792024e7420beb50739bd21n/aMirai