URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.133.58/skid.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3573473
URL: http://154.205.133.58/skid.arm
URL Status:Offline
Host: 154.205.133.58
Date added:2025-07-02 02:13:09 UTC
Last online:2025-07-23 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-02 02:14:12 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:21 days, 20 hours, 35 minutes Bad (down since 2025-07-23 22:50:07 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-21skid.armelf 4c72b3a3e372704eb64e1f0e9ebd021902928fa8c6df47e15a347fa682d48916n/aMirai
2025-07-16skid.armelf bf7602722bab8a304f4a03a9fed97ad0573a366f3db35dade4047dd1b5ba8388n/aMirai
2025-07-13skid.armelf 0195e9f425e48b57099bcf71a46a2d702fbb77e57b84f2527a86246b80191eb4n/aMirai
2025-07-11skid.armelf cbff0804335ce92de0ba1ad4c2a2ce08d89c47b64bbf9826d5331eb67843ba85n/aMirai
2025-07-08skid.armelf fbead70b377eb3eae47e5e2a53ecd430306a17d98076218feea712f8fbc5e58an/aMirai
2025-07-08skid.armelf b92ca4e7bb3fb794d9e56d85eff80e609230f7a71f3607b76d6789fff1cfd4can/aMirai
2025-07-07skid.armelf 7a285e426824bf7ff48169eb7842784610e91c906c90e5d4270b56774e25b06fn/aMirai
2025-07-03skid.armelf 2c426c7258e7a7499f88c60b15b8ce60a7edd2877422484a5f81511387de093en/aMirai
2025-07-02skid.armelf c8a80aea735ef1e418a31a11de3815fb0ee0d1a641c35c96542bcd6b034b2c4cn/aMirai