URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.124/b1n/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3687236
URL: http://78.153.140.124/b1n/arm
URL Status:Offline
Host: 78.153.140.124
Date added:2025-10-25 15:04:09 UTC
Last online:2025-11-11 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-25 15:05:19 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:16 days, 15 hours, 35 minutes Bad (down since 2025-11-11 06:40:48 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-02n/aelf 6d36a432aa0165f19b64365eb1339c9ad2593d2fb49db18581654042f67390bfn/aMirai
2025-10-30n/aelf d033e10686e1a60089fd1c6439f1531a98e388de0a071c02dfd39d7b3f6210dbn/aMirai
2025-10-30n/aelf 645823dba1b0a3c920ea433b12b66df271c935b01efa3ae48a28b6b9dd7ba328n/aMirai
2025-10-29n/aelf dc81a05fd89c7950ee64f8f3959c8ba3c960a4dc38c38b41a7416712b9bba00dn/aMirai
2025-10-29n/aelf 2e13f9d1be618452f82d145c3c8f67b9e9ba436a1a80cfdce199ca3e4ddfb19fn/aMirai
2025-10-28n/aelf ad16408499ca43a4bd96d239a768c07316329c1db5b309ca4a3d09f01c507b89n/aMirai
2025-10-28n/aelf aa494ce4d3a15855c8980f87a912e65faf59bfbf4229e53191b6b0ebea803c41n/aMirai
2025-10-25n/aelf 81f5ce9bfdb449d25da5852d26a5505532a7ec8187a6e281c6afe3c1b2625296n/aMirai