URLhaus Database

You are currently viewing the URLhaus database entry for http://45.135.194.43/bins/Tsunami.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3542181
URL: http://45.135.194.43/bins/Tsunami.arm5
URL Status:Offline
Host: 45.135.194.43
Date added:2025-05-12 17:47:07 UTC
Last online:2025-05-16 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-05-12 17:48:07 UTC to abuse{at}pfcloud[dot]io)
Takedown time:3 days, 22 hours, 11 minutes Bad (down since 2025-05-16 15:59:22 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-16n/aelf 99bebadd78994cbddd0102281a400751050338ee7c6f1926f29093c966b6a0e5Virustotal results 25.81%Mirai
2025-05-13n/aelf 21111f332b2b4e9dddd3c26c7da6e2cf5c7b60bf556ecd3a781f067100650fa6n/aMirai
2025-05-13n/aelf 39370087c8dbc116c5ae4736a63931b0f181f21a519f2dff0b9ec4c6703e3e23Virustotal results 25.40%Mirai
2025-05-12n/aelf 483d3e76bf819a477a7be79b5c771038e98cb238f55ead2db0a2aea9f4ad6ebfn/aMirai
2025-05-12n/aelf 2e8d860f18e38ce74163f61fc612532671a8400f9cc526d5a222286786bb281dn/aMirai
2025-05-12n/aelf e2f1a149f2ccb67b6a4832dcb5f0fd92396cb16965004d471eb5f21f44a64013n/aMirai
2025-05-12n/aelf 0be678970a6dbd917be87a8cffc7c015790704bf8ea6a3f213f051f0965b3a7cn/aMirai