URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.224/aarch64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3614078
URL: http://178.16.55.224/aarch64
URL Status:Offline
Host: 178.16.55.224
Date added:2025-08-30 06:26:14 UTC
Last online:2025-12-15 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-30 06:27:12 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Takedown time:3 months, 16 days, 22 hours, 40 minutes Bad (down since 2025-12-15 05:07:24 UTC)
Tags:CoinMiner elf geofenced redtail ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-10aarch64html 00be7f643a12ac2221c9ba8df4fb34b3701c336fa830d24fe906c55364ef7b35Virustotal results 27.42%
2025-11-15n/aelf dbb7ebb960dc0d5a480f97ddde3a227a2d83fcaca7d37ae672e6a0a6785631e9Virustotal results 17.19%CoinMiner
2025-11-12n/aelf 54b2d5f2a6f711e3b9d6d23466b4d841137b61518d49d432d265af931a797b0aVirustotal results 10.94%CoinMiner
2025-10-29n/aelf 0c7ce0368ae6fa3a1445b52c6d0e9f4a773cf0079601d0b5ece266837473c157Virustotal results 17.19%
2025-10-27n/aelf f6002d4b799bea2f4d563194b8bb6fabc7332c2f2b638c5d358aeb8a8bba0803Virustotal results 12.70%
2025-08-30n/aelf 89782d8142297907c9962eebdae29c28df86805a99f38a683ab55c8fa1596dd8Virustotal results 51.56%