URLhaus Database

You are currently viewing the URLhaus database entry for http://23.95.226.157/LjEZs/uYtea.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984297
URL: http://23.95.226.157/LjEZs/uYtea.arm
URL Status:Offline
Host: 23.95.226.157
Date added:2022-01-17 19:02:05 UTC
Last online:2022-03-03 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2022-01-17 19:03:07 UTC to report{at}virmach[dot]com)
Takedown time:1 month, 14 days, 16 hours, 47 minutes Bad (down since 2022-03-03 11:51:02 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-05n/aelf 93bdf87af578cb55a875c518d7f21d65673cdaa081890ddc22ccbcda3a4bb0d9Virustotal results 51.61% 
2022-01-20n/aelf ebd80fdeb08fbf95f950a658768c44c922a46a932f42afdf3c3a387b0065dcb5n/a 
2022-01-18n/aelf 24efa8130d3a2a454159adf29cd4016bcaa0b387bcc3d2742b08c2c34553af83n/a 
2022-01-17n/aelf 2e8e68c5dcea75c535af351633d2cd2efa6de6c1891dda61b4d66704e4c8e984Virustotal results 51.67%Mirai
2022-01-17n/aelf 2c0218a1093d41fe3a1f22f5de146b7167c637e71001144dd9a708af7d197b12n/aMirai