URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.66.20/bins/xnxnxnxnxnxnxnxnmicroblazexnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3692742
URL: http://196.251.66.20/bins/xnxnxnxnxnxnxnxnmicroblazexnxn
URL Status:Offline
Host: 196.251.66.20
Date added:2025-11-01 07:33:13 UTC
Last online:2025-11-09 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-11-01 07:34:15 UTC to abuse{at}nybula[dot]com)
Takedown time:8 days, 5 hours, 50 minutes Bad (down since 2025-11-09 13:24:51 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-09n/aelf 9c39e17d4a433c1f3dbd60f57c024c90145581fcf2fdaa428e23675f7b9a01f5Virustotal results 3.17%Mirai
2025-11-03n/aelf 3b208b9e5740d0e36625e6386657e530b60ae187fa993ed5160e71c7bc630e4fVirustotal results 1.56%Mirai
2025-11-01n/aelf e4167667d31db1e9e616d84ca71dcb488dfb4f71c3cce5896473027a452109edn/aMirai