URLhaus Database

You are currently viewing the URLhaus database entry for http://64.89.163.109/israel.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3773398
URL: http://64.89.163.109/israel.x86_64
URL Status:Offline
Host: 64.89.163.109
Date added:2026-02-07 04:05:09 UTC
Last online:2026-02-22 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-07 04:06:11 UTC to noc{at}miteflux[dot]co[dot]uk)
Takedown time:15 days, 3 hours, 2 minutes Bad (down since 2026-02-22 07:08:32 UTC)
Tags:elf gafgyt link geofenced mirai link opendir ua-wget USA x86

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-16n/aelf ab84b93c7e9aa0a811f47eea8ac56fefc0556d98d9bf2ba50ea95d488b4d8257n/aGafgyt
2026-02-15n/aelf 984a0cd9cec096362928ed2847a0745184fda7c2f66082733cc1a097a81b09e3n/aMirai
2026-02-15n/aelf bbbb2273d9cc7ae78b271ab36978281caefa16dc54848de9a8bbbc98b8f0765bn/aMirai
2026-02-14n/aelf a12651c0e7f050689128f648783e649cf39e66b6b607445ef000c20b923fab26n/aMirai
2026-02-07n/aelf 7030a1ac2ab03624e3d90642fd689751637f35a6cb471f47855933f8401270a0n/aMirai