URLhaus Database

You are currently viewing the URLhaus database entry for http://94.156.177.146/389242390482/nuklear.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3275757
URL: http://94.156.177.146/389242390482/nuklear.arm5
URL Status:Offline
Host: 94.156.177.146
Date added:2024-11-04 17:28:07 UTC
Last online:2024-12-01 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-11-04 17:29:08 UTC to abuse{at}virtualine[dot]org)
Takedown time:26 days, 15 hours, 43 minutes Bad (down since 2024-12-01 09:13:02 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-07n/aelf b30d7c9c00fead46f75600cbc55451b4973f583a6d45d6336e4c778f86dcdbb8Virustotal results 54.69%Mirai
2024-11-07n/aelf 75e9308aec129beb8ebdff741f7322bbdc56931ca8e61ce08504700b6efaf4fbVirustotal results 52.38%Mirai
2024-11-06n/aelf 78e7c4ae593d387e79a2e3ac952bdbd948840166545fbd4fff2acc539f3fc9deVirustotal results 51.61%Mirai
2024-11-06n/aelf 7636f3103ae51ade0b8c5603577c31bfd283352400c88b37f30fc98eaae3bb2cVirustotal results 58.73%Mirai
2024-11-06n/aelf 7949169e7c3574a7360f2ab64929676a05603ada45e43b96a4b7b0a31ffa2a2dVirustotal results 48.44%Mirai
2024-11-05n/aelf 7b0a36329497493307d399449289914c26930459c0427e4eaa091aceca65e975Virustotal results 48.44%Mirai
2024-11-05n/aelf 9b704ca18fdc393b535b8ed13f21b7b736a619e67695f5bbad3cf16a0917af95Virustotal results 49.21%Mirai
2024-11-05n/aelf 9ffa77b8332a07822c1ce522bbd3cf318e6b2952509c4c450f99c477c749397an/aMirai
2024-11-04n/aelf 74a77792cc1028ca2a8a62315d4601bfe85470d825b824b217d5c2b39fe5864dn/aMirai