URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.90/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3305153
URL: http://45.125.66.90/arm5
URL Status:flame Online (spreading malware for 1 year, 0 month, 18 days, 8 hours, 37 minutes)
Host: 45.125.66.90
Date added:2024-11-26 12:33:06 UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2024-11-26 12:34:10 UTC to admin{at}serveroffer[dot]lt)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-08n/aelf 788e47fcc1f7e85da5b575ddeb98980fafc9cab532c378855556d679da2a59beVirustotal results 59.38%Mirai
2025-08-19n/aelf 5850e0c4ff26973e6ff35c49aee574328d2342966ea96318f4b4ed61c7e8ef86n/aMirai
2025-08-18n/aelf 8359528542f4b54d754a864e5affa23ef60d54e319deda220f52d9a9138216e6n/aMirai
2025-08-18n/aelf 34c73356a072038100195ca6da0e172b6657b169911e49ed797167027bf0a8a8n/aMirai
2025-08-14n/aelf f7adca8fa8c5cf59567c026045a2ec8b4c419b0aa3250dd50dd5c06fbb05b7afVirustotal results 44.44%
2024-11-27n/aelf 9b15b0254a4becfab3b3842cdf6c46a27de624c4985e4e08c4d58d43e9db082dn/aMirai
2024-11-26n/aelf 9a7e77eff17b6bab95e53989adca31512823cf0c92a342a1b7e2ca445d9bb560Virustotal results 53.12%Mirai