URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.133.58/skid.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3573448
URL: http://154.205.133.58/skid.arm7
URL Status:Offline
Host: 154.205.133.58
Date added:2025-07-02 02:12:09 UTC
Last online:2025-07-23 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-02 02:13:11 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:21 days, 20 hours, 51 minutes Bad (down since 2025-07-23 23:05:03 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-21n/aelf cac1f84aafd6f3b5d144e2bdad81f759d12515d73fac77cb8ac09678f2c28f52n/aMirai
2025-07-16n/aelf 8cffa15900953602ab7399ebea75f5523c5aab3e6b24a43635989972d43848cbn/aMirai
2025-07-13n/aelf e97303ce24d923c81141ea75392024b2de3f4b228796afc6418357a0fd31a7bcn/aMirai
2025-07-11n/aelf 55a14313fb81153146f9c7bc2617a3a1c969ada95104bdc625cde73285aca80an/aMirai
2025-07-08n/aelf ee1d4983ba52d63d66247c209c3a0a7aabef4321ef91e7ce156f3028fcdbf838n/aMirai
2025-07-08n/aelf 4af7d510597b1775ab8f590f6457f8a65aa68e3926b57ee812e33b1eda139403n/aMirai
2025-07-07n/aelf 3f99ea4c8a795055d607f829d1fe7e149c25badefbe66930a53d4ee4350815a0n/aMirai
2025-07-03n/aelf d1b63ef97da67e4e9a0baa5b786242ac39c2dd3b05f26e989c321d06012583bcn/a
2025-07-02n/aelf e5d38157cc5453f5f9ad26446a978f0a303990067ee041a364736db2d78535ffn/aMirai