URLhaus Database

You are currently viewing the URLhaus database entry for http://93.123.109.218/test/armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3581110
URL: http://93.123.109.218/test/armv6l
URL Status:Offline
Host: 93.123.109.218
Date added:2025-07-11 06:36:28 UTC
Last online:2025-07-18 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: xqtsmvjnxuurv
Abuse complaint sent (?): Yes (2025-07-11 06:37:12 UTC to dmzhostabuse{at}gmail[dot]com)
Takedown time:7 days, 17 hours, 13 minutes Bad (down since 2025-07-18 23:50:19 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-13n/aelf a70d6c5aa29c661fc8c25ac9c8658af00a90c631b65df818110cc960fa4ecb7fn/aMirai
2025-07-13n/aelf fced14833d7f2dd581aff8cfa7390e5b88601233db10bbc4ec4a0d66baf17d7fn/aMirai
2025-07-12n/aelf 7e7c53897eb1f9c7b1f36a4f2950a4d8eac4ea150c382f3577fb4e74caeefc7bn/aMirai
2025-07-11n/aelf 004a1d28b4d9eac58e5883eac29cec0f0e43eeb12abda8e3fc70d081918dd754Virustotal results 21.88%Mirai
2025-07-11n/aelf 14e979890382271850fcfa105dc97d1d3bc5176565ebcb59c1ae334d3a2d539aVirustotal results 55.56%Mirai