URLhaus Database

You are currently viewing the URLhaus database entry for http://160.250.134.51/skid.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3620080
URL: http://160.250.134.51/skid.arc
URL Status:Offline
Host: 160.250.134.51
Date added:2025-09-08 15:52:16 UTC
Last online:2025-10-04 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-08 15:53:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:25 days, 11 hours, 26 minutes Bad (down since 2025-10-04 03:19:41 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-21skid.arcelf a7ce2785a746d714cd6407d2a8ef07c9d510e10b46f0f8d0d4a266cc16774a57n/aMirai
2025-09-21skid.arcelf 5dd8295dc7af5ad62d02f93bb7affc29c1206541356bfb1d90efa7cbcf94fc3fn/aMirai
2025-09-18skid.arcelf 8ed30a24addbae5a6c1bc5f4cc3bc3a0e977bae90199379f14a1a89915ef1754Virustotal results 37.50%Mirai
2025-09-14skid.arcelf 1bdaf68bc822be942542b352bcb9b575dbce72161da6042b7d14444a35f3cdc7Virustotal results 18.75%Mirai
2025-09-12skid.arcelf f33bccf88f58f7b6e5cc024b04fc546c229888d07e8a754779f0e8fab533be1aVirustotal results 35.94%Mirai
2025-09-09skid.arcelf 5ec862d0b3d5a76e7005e8ff9c28850861d9b60fc9a7d5448b8230190a86fc25n/aMirai
2025-09-08skid.arcelf 0ea1e64d1ba217c29dc7a2151c996c9313fe02709a8be4ce54afa79ea24017bfVirustotal results 35.94%Mirai