URLhaus Database

You are currently viewing the URLhaus database entry for http://www.b0tnett.duckdns.org/main_x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3781933
URL: http://www.b0tnett.duckdns.org/main_x86
URL Status:Offline
Host: www.b0tnett.duckdns.org
Date added:2026-02-20 16:48:28 UTC
Last online:2026-03-15 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-02-20 16:49:21 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:22 days, 10 hours, 35 minutes Bad (down since 2026-03-15 03:24:45 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-28n/aelf 5f8431274ea95602832321195e6cbd0dd594966b8218e836d1a9d50d1fd2c681n/aMirai
2026-02-28n/aelf b775b53d510aa1b5b8ef7db69e7e19c5809024470419cd0b7dd4206518f28344n/aMirai
2026-02-27n/aelf 674b3ee885ff0c6e1091dea19844daa7cd75d3418357ea49705309997954b4f8n/aMirai
2026-02-27n/aelf d21a18bb2bf6195c81274399d8218bb0890a6a7531ccc133b2ca910676f802fan/aMirai
2026-02-24n/aelf 758bc5167f7893aa61c962eeaea79dcfc0041ab32cbee7748cca1e7089508eaen/aMirai
2026-02-23n/aelf cc6b78ba8ceb28bf23b30dd287c1be9ee6e0f662b78ece677c8ad6d2efa85ceen/aMirai
2026-02-22n/aelf e25cf2975c9b954f57f9806856751985b482070d836f26ccd8431fcb5f030e7en/aMirai
2026-02-20n/aelf 4f2e5b2fc493885cb048ee9d092ee74a34cd0e8ffa80ad09d813d9a853d866c4n/aMirai