URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.56/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3464150
URL: http://45.125.66.56/arm5
URL Status:Offline
Host: 45.125.66.56
Date added:2025-03-03 11:46:05 UTC
Last online:2025-09-28 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-03-03 11:47:06 UTC to admin{at}serveroffer[dot]lt)
Takedown time:6 months, 28 days, 15 hours, 49 minutes Bad (down since 2025-09-28 03:36:54 UTC)
Tags:ddos DEU elf geofenced mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-23n/aelf ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7Virustotal results 57.81%Mirai
2025-03-03n/aelf 871efbc06770e36cd240f3cb7add2e412f2beb8a6465d610c54b1234532034a2n/aMirai
2025-03-03n/aelf 3d86ce610d93f2cfb4b2edb6d1431d7e14dddc21fe958d2f07623b276f4cbe9en/aMirai