URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.92/upl04d/cl13ent/edu.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3657396
URL: http://78.153.140.92/upl04d/cl13ent/edu.arm6
URL Status:Offline
Host: 78.153.140.92
Date added:2025-10-05 06:18:10 UTC
Last online:2025-10-08 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-05 06:19:22 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:2 days, 22 hours, 37 minutes Poor (down since 2025-10-08 04:56:29 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-07n/aelf c515318e8341874ac1c6ba68ba8e1ed810a49e11ffbe72dabd5e42867ddfb266n/aMirai
2025-10-05n/aelf 8d80d1012d49f6643feff086bbd439f6d0d387903db75e65ca8a4d302b3e243aVirustotal results 26.56%Mirai
2025-10-05n/aelf 1e9990be1b66f367f926329009a5cab4e9d74d6eeb1fa9dde67e450ce1621be6n/aMirai
2025-10-05n/aelf 0c943232076c8af306dc8745a8848a37c7586bc3bb7a226b967e84250b5aabdbn/aMirai