URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.37/bins/Hilix.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2132212
URL: http://2.56.59.37/bins/Hilix.arm
URL Status:Offline
Host: 2.56.59.37
Date added:2022-04-05 03:14:04 UTC
Last online:2022-04-15 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-04-05 03:15:07 UTC to abuse{at}serverion[dot]com)
Takedown time:10 days, 8 hours, 3 minutes Bad (down since 2022-04-15 11:18:20 UTC)
Tags:32 arm elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-14n/aelf 2eb75157bc74dc59a607f2004f3bba32bc17c1554235adcd6717ced4f17e961fn/a 
2022-04-13n/aelf 5899ddb88f3c38dd26c6aa18073717a00ee9939074339aa4c13b68f1006d40eaVirustotal results 21.31% 
2022-04-11n/aelf a3dcc3888a7aac9321839c19a97ed9c3bc4bc34e279699e504c0fa0840712b32n/a 
2022-04-11n/aelf 42348faea08b288c7f8449be2d27787239f43538f2ceb20aa2a386c177a9e232n/a 
2022-04-10n/aelf 15c3e6467999b0882118a90eeb8084836db37585188739d01f22e9d4acb87ee5n/a 
2022-04-09n/aelf 6b1de2a44a27d1a0d1c951f98c4abe2b0cc3b8c7a830dcbe9c9f23324a90dfc7n/a 
2022-04-05n/aelf f4ec48480fb62ba10b0d074ace20531ef8432b9d570e5e31fff4c0611dcf65dbn/a 
2022-04-05n/aelf 37ad7ac22dfc857b9f890576a1d4cc558fd43f9f6f616870054b2a15a5ff3fdcn/a 
2022-04-05n/aelf c416d134533f9e9458c0ac5e05bcc433b4cceace43d02058cccee7d299b001daVirustotal results 57.38%Mirai