URLhaus Database

You are currently viewing the URLhaus database entry for http://154.216.17.126/arm4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3298546
URL: http://154.216.17.126/arm4
URL Status:Offline
Host: 154.216.17.126
Date added:2024-11-21 19:42:05 UTC
Last online:2024-12-02 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-11-21 19:43:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:11 days, 0 hours, 56 minutes Bad (down since 2024-12-02 20:39:28 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-01n/aelf f1b532998af2e91b11f9e2bc393fcf5cbbf36f30ae716f7d409940f146ed51d7Virustotal results 51.56%Mirai
2024-11-30n/aelf b7aedc845871a2577aef775d5d786040db78488978fc0ad7d76011a4320ecb5bVirustotal results 54.84%Mirai
2024-11-30n/aelf 98654eb81cee57fdca8c83242ac73dfe944a0fe79c37b5385863760a48e0b712Virustotal results 17.46%Mirai
2024-11-30n/aelf 91552239c42140b545821b4f22300f3c880c0df1d17fb31b89d29ff2423cd545n/aMirai
2024-11-21n/aelf c93071a6501aee72148e493997e3eb5cd17228de0cc1d751475bd74c029090een/aMirai