URLhaus Database

You are currently viewing the URLhaus database entry for http://definitely-not.gay/x-3.2-.dick which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3777393
URL: http://definitely-not.gay/x-3.2-.dick
URL Status:Offline
Host: definitely-not.gay
Date added:2026-02-13 20:07:11 UTC
Last online:2026-03-07 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-03-03 02:16:12 UTC to abuse{at}ghostnet[dot]de)
Takedown time:1 month, 9 days, 20 hours, 16 minutes Bad (down since 2026-03-25 16:24:51 UTC)
Tags:botnetdomain mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-09x-3.2-.dickelf da808c541f3d5a295f96863e1b605b23cdb7f69a2e2bc5d017a1c4616c1298cfn/aMirai
2026-03-08x-3.2-.dickelf a4d21fcfe726542642e7e4b17141ad84ce882f691a56e36c3279c56c286f951an/aMirai
2026-03-06x-3.2-.dickelf 84dc78acf07c09ff8547999bce9a5da80cb330a2d1d227908c4421182550f461n/aMirai
2026-02-13x-3.2-.dickelf ef15218a93fd7274e3904f9e58831fea865d69020a91635b0bed69379b22ab41n/aMirai