URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.126/loki.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2759966
URL: http://5.181.80.126/loki.arm
URL Status:Offline
Host: 5.181.80.126
Date added:2024-02-12 05:40:09 UTC
Last online:2024-02-16 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-02-12 05:41:06 UTC to noc{at}4vendeta[dot]com)
Takedown time:3 days, 21 hours, 9 minutes Bad (down since 2024-02-16 02:50:22 UTC)
Tags:32 arm elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-14n/aelf 38012e9515b193ee718dc1281b36761c66f704a8d67f078f429d785e7dbb1e80n/a 
2024-02-14n/aelf 350dc9ca08ba33b93dac2f5952167a5d70d1307135136b526c608a46d8d0381dn/a 
2024-02-14n/aelf 54556722a279c3f8f5989e8236b4787dcef69c1d435b4078b66fdd156019775bn/a 
2024-02-13n/aelf 744142c8c20720d994e05e8cb925726e394495f15de63080c1a0cc377f6cfb17n/a 
2024-02-13n/aelf d0cf8ff832ee17584c68a557e66977d386b2b64c7f49d8032d4e9c015237f12bn/a 
2024-02-12n/aelf b120ffefcd786fea2e15545cbd70b148582da4524b523f31dabd5932b40a5bddn/a 
2024-02-12n/aelf 6907d1a558b3460292266a1629593360a710906f84e7bf739999416303ac658bn/a 
2024-02-12n/aelf 7afe2cdec955d84518a5fe43a5726b02b93a054a256f450e8657b0b250eb2dc2n/a 
2024-02-12n/aelf 47cfa23a93365f627cf5047a987ae69c86b4f443747adf18de24877b7d90690eVirustotal results 17.74%Mirai