URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.56/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3464149
URL: http://45.125.66.56/arm6
URL Status:Offline
Host: 45.125.66.56
Date added:2025-03-03 11:46:04 UTC
Last online:2025-09-28 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-03-03 11:47:05 UTC to admin{at}serveroffer[dot]lt)
Takedown time:6 months, 28 days, 16 hours, 17 minutes Bad (down since 2025-09-28 04:04:33 UTC)
Tags:ddos DEU elf geofenced mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-23n/aelf 5e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31Virustotal results 56.25%Mirai
2025-03-03n/aelf 7d8505af5580d7e7caec799b3bd2341c9d32f4bb14bee4a04175cfad4376cd98n/aMirai
2025-03-03n/aelf f7e0cda274e3f657c209d9e6045b98adc896669c0a4193c6c7fcfb8543b15316n/aMirai