URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.124/b1n/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3687233
URL: http://78.153.140.124/b1n/arm5
URL Status:Offline
Host: 78.153.140.124
Date added:2025-10-25 15:04:09 UTC
Last online:2025-11-11 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-25 15:05:19 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:17 days, 8 hours, 47 minutes Bad (down since 2025-11-11 23:53:13 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-02n/aelf c4a1f4db8f6a5c9a040403905726c6d56d448eff3654765283fd7c768a881a87n/aMirai
2025-10-30n/aelf e98c441f99727eadd918f45230cda043a63d78143c608b87a668b36ebe4956f9n/aMirai
2025-10-29n/aelf 7eec3afbdee13e805c06130106e5210fa7a7781e46286443474a23297c11c692n/aMirai
2025-10-29n/aelf 69f6203bf83049d1cd8e71c257869a2d9980d04d1e9a51c439117930ef810c7an/aMirai
2025-10-29n/aelf c263c396faf1ecd626cabf78590e2377d6426d47696024356936f9ce43d6e346n/aMirai
2025-10-28n/aelf 773e664928edc197638a464f753efc7b3fb59ec026b7545ee51e53243c767630n/aMirai
2025-10-28n/aelf c85b67faa04393ca57d8a65f7d3dcc78b7e76ab68453c456c9210dbf9623bc64n/aMirai
2025-10-25n/aelf ab88f19527cbf200cd0d0e619f93a69a36183a60a9498fd87308a034c4ed2909n/aMirai