URLhaus Database

You are currently viewing the URLhaus database entry for http://45.135.194.43/bins/Tsunami.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3542179
URL: http://45.135.194.43/bins/Tsunami.m68k
URL Status:Offline
Host: 45.135.194.43
Date added:2025-05-12 17:47:07 UTC
Last online:2025-05-16 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-05-12 17:48:07 UTC to abuse{at}pfcloud[dot]io)
Takedown time:3 days, 23 hours, 0 minutes Bad (down since 2025-05-16 16:48:21 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-16n/aelf d980ea20258d480e3f0de0ec4db24a65ee3b90ee277df2098ddc201b674cf7c2Virustotal results 46.03%Mirai
2025-05-13n/aelf e6ac737b3948c4ab2138ff8d3ebfa51552b71860ed61733374350843bf508ed7n/aMirai
2025-05-12n/aelf 9ed10712b95fe1459730aef4cc9cb6ea863966c86c9a043197110b04380f3d13n/aMirai
2025-05-12n/aelf c7aae653bff2d90cdbf9261a1501f9e524071bda1c202770a50535f159f3cd2dn/aMirai
2025-05-12n/aelf d489ad9e2f12633d325b61ed33a076c0f62a21a6387b0532f226805749b1c51bn/aMirai