URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469861
URL: http://154.205.128.91/zd/arm6
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:29:02 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:30:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 7 minutes Bad (down since 2025-04-16 14:37:17 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf feec14ab9c4fe8cdb71d6a762178a491581be4ab3ac43e42d7608c3b0dc8a50en/aMirai
2025-04-12n/aelf 8a35a8593a850c844142e3fb8805a264ec2ca10c1838f5598a55742587305c38n/aMirai
2025-04-02n/aelf d022f7204a6e9f8bd6fbf249023f0473f207a8f1b8d09e31d2edbd5ad5f2b415n/aMirai
2025-03-25n/aelf 4581d19d7171c1f7f8350aee1d323920f19c524726ff20031cae87288488a0ean/aMirai
2025-03-11n/aelf bacd5592d06965a814d3ac9258ee442d2f8bd8bef545f06e0395f698dc4a22b1n/aMirai
2025-03-09n/aelf c457ac0b47cbf39ea2573843fe1f54db4fd784f85b52c05a04fda1c72b6085c5n/aMirai
2025-03-09n/aelf 3009e63d37bda64b7eddd60f34627ac8997fbf8f2294670d84cc39f717fc36d4Virustotal results 7.94%Mirai
2025-03-06n/aelf 5b1ab831139243bfa5880a5c1f074f76c5a173b88626619013d916bb93672e6fn/aMirai