URLhaus Database

You are currently viewing the URLhaus database entry for http://42.112.26.36/zd/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3472002
URL: http://42.112.26.36/zd/arm5
URL Status:Offline
Host: 42.112.26.36
Date added:2025-03-09 07:28:07 UTC
Last online:2025-04-07 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-09 07:29:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:29 days, 13 hours, 14 minutes Bad (down since 2025-04-07 20:43:34 UTC)
Tags:elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-26n/aelf 2fe73469585483a503006d519deaa40b780cc4874a583d7e568173bc4bece315n/aMirai
2025-03-15n/aelf 580af952cb77ef868e73641910ed19c8967cdfc52b64a32f42c9e1a31ff5ab41n/aMirai
2025-03-11n/aelf ea6cbd637f26c0ebf1181a7ac2187b7530d918a360eaeb4ef8dea5da6f152673Virustotal results 7.94%Mirai
2025-03-09n/aelf c8e46702d120d5eb5eec3b35ff68e8ea434a5e4131371b14c59ded744d56e415Virustotal results 14.29%Mirai