URLhaus Database

You are currently viewing the URLhaus database entry for http://94.156.177.146/389242390482/nuklear.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3275756
URL: http://94.156.177.146/389242390482/nuklear.arm7
URL Status:Offline
Host: 94.156.177.146
Date added:2024-11-04 17:27:09 UTC
Last online:2024-12-01 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-11-04 17:28:08 UTC to abuse{at}virtualine[dot]org)
Takedown time:26 days, 15 hours, 53 minutes Bad (down since 2024-12-01 09:22:07 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-07n/aelf 665479c45de45cd8b54eb6bb099764de5e1f689609a27660c026fbf097ef6325Virustotal results 56.25%Mirai
2024-11-07n/aelf 834ffbe44772c6acb3ae3abedee68decb8ba3c848f9889b1245161c05dcb23dcn/aMirai
2024-11-06n/aelf 01a8bdaed1410bb3e65089d036943a747ebb1325f61d3b14d01bd5649485e82dn/aMirai
2024-11-06n/aelf 5ababfb717882367642d69cb70846a1e319becde91c6599b19d63c748a282f01Virustotal results 61.90%Mirai
2024-11-05n/aelf f704f0361167c3aeb5a3eee160c10b727f363bf93f305150a033a4ffbda6d799n/aMirai
2024-11-05n/aelf da00c1948fed96275fb4d150db15cf050b817aeb3d8fded35d03349c9fdf0c89n/aMirai
2024-11-05n/aelf f3ec009216bae02bfbf05a82c809fd4bbb071123a4a98438db4475bc727274fbVirustotal results 61.90%Mirai
2024-11-04n/aelf 0bafde984e6d5f4ef369f2249033e7bb4d2f539023b6869ea48004e8a318c2d5n/aMirai