URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469855
URL: http://154.205.128.91/zd/arm
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:28:04 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:29:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 25 minutes Bad (down since 2025-04-16 14:54:41 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf af09b1305e224dd5a3edf4d4b9dea3f8f3acfc3a4b08e4c91df6a50f1d7d3950n/aMirai
2025-04-12n/aelf f4adcaeb1637a7912630ee4b0eb34e5d431c4e827832e34410dd65ddb75e7303n/aMirai
2025-04-02n/aelf 3d630b1a40a96b505a9ab440d07319bf9f71b5ea81aa43915e2455d0824cc72bn/aMirai
2025-03-25n/aelf dc722c44d33686821c5dc6c4da86caa3196af488b920959fe974f8d988b08419n/aMirai
2025-03-24n/aelf f747f5a199fe1960ff92334a4179ec83efa620cea88d87be5e2cc52a41994557n/aMirai
2025-03-17n/aelf 5764445093843f49557cfbbea76d2aa5a1a018dc45e9e79b81cfadab791accf7Virustotal results 38.10%Mirai
2025-03-14n/aelf decdfd7cfdcf4682602d868916d630051180ec3e81f0f5f86ed0196afd234893Virustotal results 10.94%Mirai
2025-03-11n/aelf d52521e02d2c61e1f3b7584e86b63059714836463589a551f966940ae474bba4n/aMirai
2025-03-09n/aelf daeb5ef3b26da7c9145e44902c0aa0ee51850dfda25276f37f36c7d346a96781n/aMirai
2025-03-09n/aelf e619c5f92053aaa1519f2842eb66fcf59838bd9aac57964d886ee0711b85c3e6Virustotal results 14.29%Mirai
2025-03-06n/aelf bb58c0fef6bb4637521695835aa538129a82633b9cb6716bb326da79bc2c360bn/aMirai