URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.92/upl04d/cl13ent/edu.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3657395
URL: http://78.153.140.92/upl04d/cl13ent/edu.arm7
URL Status:Offline
Host: 78.153.140.92
Date added:2025-10-05 06:18:10 UTC
Last online:2025-10-07 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-05 06:19:22 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:2 days, 17 hours, 25 minutes Poor (down since 2025-10-07 23:44:43 UTC)
Tags:arm elf gafgyt link geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-07n/aelf 3677ced116cd22cd7084d464eca7be4d8405565c41ef6a16e8c77e229f5facfdn/a
2025-10-05n/aelf b622a7b848a9846e2af4f8f985777bb8d095b8eb56d57a502f97d446cfe82e9bVirustotal results 23.81%Mirai
2025-10-05n/aelf 795d94545d67996683894b1fa0d5449f961e01266825c5d0aeb7c67026b22606n/aMirai
2025-10-05n/aelf a185ebc407472e4cc5d1ffd582a7ce660ca17e62e2b80bf0cc9efb0cbcfe15b6n/aGafgyt