URLhaus Database

You are currently viewing the URLhaus database entry for http://www.teamc2.duckdns.org/bins/spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3722822
URL: http://www.teamc2.duckdns.org/bins/spc
URL Status:flame Online (spreading malware for 22 days, 21 hours, 28 minutes)
Host: www.teamc2.duckdns.org
Date added:2025-12-02 05:05:22 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-02 05:06:17 UTC to report{at}abuseradar[dot]com)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-15n/aelf 07019ea27232f2c0f528115a443e5b61fc45a53b05ccc28f60496ddd8a08b40an/aMirai
2025-12-13n/aelf ade5e04e67d0ba5d6530437109c0829ecf6313bb73d7d9de7459b0156cbeccc1n/aMirai
2025-12-13n/aelf edfa3890e5a7f73a998f6a86141ae03540d409523e9f14e88c2f5e8919e99f66n/aMirai
2025-12-03n/aelf 3bd64f85ca4ab7de19efae6a160bb24c1553182efa8aca8de17c7704ebaf5117n/aMirai
2025-12-02n/aelf 2128a1f811a4afe9324e53259295182adc3872f3c01ac54367264e2e851f8b60Virustotal results 48.44%Mirai