URLhaus Database

You are currently viewing the URLhaus database entry for http://vps.atlas101.us.kg:7768/flutter.arm8 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3904708
URL: http://vps.atlas101.us.kg:7768/flutter.arm8
URL Status:Offline
Host: vps.atlas101.us.kg
Date added:2026-08-17 05:38:09 UTC
Last online:2026-08-21 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: tp0x
Abuse complaint sent (?): Yes (2026-08-21 05:27:21 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Takedown time:4 days, 9 hours, 51 minutes Bad (down since 2026-08-21 15:31:14 UTC)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-21n/aelf 3057adec8768ed3d09350b72c9f199a2bbb8db1a2a2aa289969e41c95706dd7an/aMirai
2026-08-19n/aelf 61e461992a73559c092a22b2d2c8d19d7f5739f2c238faf1b05a6ec8cd10c19dn/aMirai
2026-08-19n/aelf 06478d06ab267bd30247042de787fa36e50be6b7d23093ce972167a62419b518n/aMirai
2026-08-19n/aelf 6dc28fb34364707e34a0511d2d8d82fa1825ba273ad14ac4d73b88efa5579d0cn/aMirai
2026-08-18n/aelf 58f21a0c7efee10dba3dc34fc3fefc58631f3195513518bbe7fa14fca2b68036n/aMirai
2026-08-17n/aelf 196a0bc458489424c912c8aef3d8d7b8c661d42bee6732ad300cef5dd59f0f3en/aMirai