🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://iloveanal.work.gd/armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3927563
URL: http://iloveanal.work.gd/armv4l
URL Status:Offline
Host: iloveanal.work.gd
Date added:2026-10-03 10:34:35 UTC
Last online:2026-10-07 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-10-03 10:35:24 UTC to abuse{at}swissnetwork[dot]co)
Takedown time:4 days, 8 hours, 48 minutes Bad (down since 2026-10-07 19:23:28 UTC)
Tags:botnetdomain elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-07n/aelf ca7572bfa387832fa4e8656fddb1f1ef6a5f82a3482fc0e8a38c7b3b367edff2n/aMirai
2026-10-05n/aelf 7e71a7685792289f53de52982089c87fcc022e56055ab4b997aa14c996eb2ae8n/aMirai
2026-10-05n/aelf 0632ff216d3230e1365721883414948d5db99d6671f9ef345a16a557e924cc11n/aMirai
2026-10-04n/aelf 08dec15e72a6c327ad91bd773f35b0d17bdf320bda1be6ca3398b99366b0e6ccn/aMirai
2026-10-03n/aelf 4d04a95bbc8dd80f6cf431519c0f408adbdfa6b548405148c97c1b1ded46a295n/aMirai
2026-10-03n/aelf 7b3d4d6a8c04e409b5a97d000faadbd0170ee9f82dcd52d6d5852e57a5d5439cn/aMirai