URLhaus Database

You are currently viewing the URLhaus database entry for http://64.89.163.109/israel.armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3773407
URL: http://64.89.163.109/israel.armv4l
URL Status:Offline
Host: 64.89.163.109
Date added:2026-02-07 04:06:10 UTC
Last online:2026-02-22 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-07 04:07:11 UTC to noc{at}miteflux[dot]co[dot]uk)
Takedown time:15 days, 9 hours, 19 minutes Bad (down since 2026-02-22 13:26:28 UTC)
Tags:arm elf gafgyt link geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-17n/aelf beedf77d68b043aaf0c2faaa380c291bff6d93b7af992c06731a647ee92638cen/aGafgyt
2026-02-16n/aelf 9402468443164c579f7cd8594d8707efb42ca143d1ebe3244a7c5efb9a117b85n/aGafgyt
2026-02-15n/aelf 51db00a07f92d39622967441eb67b1456f6fd4b7a2e7f6bbafd45aba19231b2an/aMirai
2026-02-15n/aelf 72900668fde35494bd8b6e6e26e2f7903dc17e2087906658d408b0f672752771n/aMirai
2026-02-15n/aelf 84b0ddf5462e970a0c4ce0d7963b4e159f61c70c6d1287dc045f932932d6245dn/aMirai
2026-02-14n/aelf 9405eff2220bd2d54d33cdd17f85a66742efd840889d76871f9ac5cc06d23ef1n/aMirai
2026-02-07n/aelf 8d23e5ad446f433f848a47afe214c5985a1e6613ad31f6b42757bf9a8fd7fc74n/aMirai