URLhaus Database

You are currently viewing the URLhaus database entry for http://87.248.150.68:84/armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3608794
URL: http://87.248.150.68:84/armv6l
URL Status:Offline
Host: 87.248.150.68
Date added:2025-08-22 05:47:19 UTC
Last online:2025-09-18 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-22 05:48:17 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:27 days, 15 hours, 53 minutes Bad (down since 2025-09-18 21:41:30 UTC)
Tags:elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-03n/aelf 06dfacf4bb22758e1743be816e982b9af64da11c4889ecf68009469a5e5b1b67Virustotal results 28.12%Mirai
2025-08-31n/aelf 992678bca86c3392510f0c3347046db0f54b8d61ea01a86ebea917357408811bVirustotal results 18.87%Mirai
2025-08-30n/aelf 764dff7fcc775cbc66933d22a2a56fdb41a0c106ffb30083ac0fef125bf89129Virustotal results 21.88%Mirai
2025-08-29n/aelf b96dc412a97f2771e17723a1c299fb4de75cb4237b214f622866641e684ed11dVirustotal results 21.88%Mirai
2025-08-22n/aelf 1fd4d57f3ac56ba6c2000cd9bc7171c1f8ae3877411d683548e02ba8f76e7c03Virustotal results 31.25%Mirai