URLhaus Database

You are currently viewing the URLhaus database entry for http://38.6.224.248/skid.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2808034
URL: http://38.6.224.248/skid.arm6
URL Status:Offline
Host: 38.6.224.248
Date added:2024-04-11 08:39:05 UTC
Last online:2024-04-15 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-04-11 08:40:07 UTC to abuse{at}petaexpress[dot]com)
Takedown time:3 days, 18 hours, 54 minutes Bad (down since 2024-04-15 03:34:37 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-14n/aelf 7dd245dd604fe8283fc92e44922ffda2e2982ce509ea92450ca9056b82914b53n/aMirai
2024-04-14n/aelf 8939ab97ce91dcb3609d4add2e7417d232c8f9e9c9546a8828ebc36083650f76n/a 
2024-04-11n/aelf bec05c1002347a33b6bb1c06b3fb9afdce1b5cc2ba56272c1b798a4c9e64773cn/aGafygt