URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.56/multi which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3464227
URL: http://45.125.66.56/multi
URL Status:Offline
Host: 45.125.66.56
Date added:2025-03-03 12:34:09 UTC
Last online:2025-09-27 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-03 12:35:06 UTC to admin{at}serveroffer[dot]lt)
Takedown time:6 months, 28 days, 8 hours, 56 minutes Bad (down since 2025-09-27 21:32:04 UTC)
Tags:404 censys HailBot mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-26multish 0356f34fa8b7a5c81823a03d1b264a9c7dac9b117d1b504665a71527f12150c4Virustotal results 50.00%Mirai
2025-08-31multish 5aad2c9f1ff36d3d5a00cb585efbd0727814fe32440257acba6f6872e89a45ffn/aMirai
2025-08-23multish 1c7dc1e3e0dc77326989815580580b8e6b4ceb36d1bf7a2e6c0838dcd2514db5n/a
2025-03-03n/ash 7c6e89399bdf2d2ef6c5a87d5ca57d710f5d329a47378000e0fe5a91dd113101n/ahailBot