URLhaus Database

You are currently viewing the URLhaus database entry for http://178.215.238.13/bin.armv5l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3239475
URL: http://178.215.238.13/bin.armv5l
URL Status:Offline
Host: 178.215.238.13
Date added:2024-10-17 11:52:07 UTC
Last online:2024-10-30 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2024-10-17 11:53:11 UTC to dc{at}perfectonetworks[dot]com)
Takedown time:12 days, 12 hours, 8 minutes Bad (down since 2024-10-30 00:02:08 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-22n/aelf e9da6121e567978810a2a2558a72319de8fd9ebae61fdec7353b8db3d48d6067n/aMirai
2024-10-21n/aelf 79b3a58480b5a8941672fa8a8ad3d8d3df45ffe4e23d120f953418e630829c47n/aMirai
2024-10-17n/aelf 4b4ecff37e4b029fd368db9d76acf0f99fbec53e7fca98e1203b0aa3203ae1a4n/aMirai