URLhaus Database

You are currently viewing the URLhaus database entry for http://103.211.218.101/yakuza.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3759956
URL: http://103.211.218.101/yakuza.x86
URL Status:Offline
Host: 103.211.218.101
Date added:2026-01-18 19:13:31 UTC
Last online:2026-03-05 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-01-18 19:16:13 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:1 month, 15 days, 7 hours, 52 minutes Bad (down since 2026-03-05 03:08:56 UTC)
Tags:DEU elf gafgyt link geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-25n/aelf 4ef0202d0b3b7cc2e39f47074faf010eb831198cd9588f7ce702722d8e24323bn/aMirai
2026-02-24n/aelf 550284b2b23424cb0e603aee47b1e3b9a6b4168b9891e2a32ecbb45cf3a26d6fn/aMirai
2026-01-30n/aelf 8d2f9b5619b96ff285f43b817366476ff3cb5bbdeac29bc9ef93804701249955n/aGafgyt
2026-01-18n/aelf 5f5421cb72d0c879831ad58b1f073817c976cc8c68c9bba0a95f98065e379d7bn/aGafgyt