URLhaus Database

You are currently viewing the URLhaus database entry for http://45.135.194.43/bins/Tsunami.spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3542176
URL: http://45.135.194.43/bins/Tsunami.spc
URL Status:Offline
Host: 45.135.194.43
Date added:2025-05-12 17:47:07 UTC
Last online:2025-05-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-05-12 17:48:07 UTC to abuse{at}pfcloud[dot]io)
Takedown time:3 days, 23 hours, 14 minutes Bad (down since 2025-05-16 17:03:03 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-16Tsunami.spcelf bdd6d6b9b6a5c36ed92b6781ae0132cf361eeb27d32e9539581564663dccc29cVirustotal results 61.90%Mirai
2025-05-13Tsunami.spcelf e03112b5d0ba4fb9aad942ac3400f9345f8016c6821128d84be34b993fc38caan/aMirai
2025-05-12Tsunami.spcelf 0fd0e01246c0313b8ebeb3bf8d9a390b1c30fb4ca54fb4aa932fef6801f16a21n/aMirai
2025-05-12Tsunami.spcelf 79f61e4ecd1c17abf494d05e29d020144470e5af69ffe534e3899f9260d39956n/aMirai
2025-05-12Tsunami.spcelf 82677ed9c4ac879eac411b788f4d8e00eaa129d62b9a28475fba551df0e345c8n/aMirai