URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469852
URL: http://154.205.128.91/zd/arm5
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:28:04 UTC
Last online:2025-04-16 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:29:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 37 minutes Bad (down since 2025-04-16 15:06:22 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf d65bf2ee0a4e7c69941ef39c64d1a4426c8ba086fc5b3e9ad01f7f15d4b3267fn/aMirai
2025-04-12n/aelf 7f581c976885ca1ea767ae8d68c123ba30d0d29e01acaea4977ac990ce1b388fn/aMirai
2025-04-02n/aelf 8b0d61491fff9ffeb51c305cc5857a8a3adbf9a6be735bb3f2c6da686186c69an/aMirai
2025-03-25n/aelf 5b41a187bd2f6557b9cf433e5f8da0984e6b72ffb99145a7017c516f16fed28en/aMirai
2025-03-24n/aelf d51de548b2bbcf3e08ea87d39e515c560f4035e8baf764d0b2e482fbfead3dc4n/aMirai
2025-03-17n/aelf 580af952cb77ef868e73641910ed19c8967cdfc52b64a32f42c9e1a31ff5ab41Virustotal results 29.69%Mirai
2025-03-14n/aelf 175f814a4c7f2beea5779be8cfd7515c22b65393d69f246f5a9fac88ee9ec82an/aMirai
2025-03-11n/aelf ea6cbd637f26c0ebf1181a7ac2187b7530d918a360eaeb4ef8dea5da6f152673n/aMirai
2025-03-09n/aelf 4dcf5bfc7c1371d882144eb30c42763fb6ed908da6da273788a50ab9b58859cdn/aMirai
2025-03-09n/aelf c8e46702d120d5eb5eec3b35ff68e8ea434a5e4131371b14c59ded744d56e415Virustotal results 7.94%Mirai
2025-03-06n/aelf b4844a86f4dfd7843233acaf625f57692f0766a2adb8a4ee7b1e66191f92b7f4n/aMirai