URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.66.20/bins/xnxnxnxnxnxnxnxnmipsxnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3692744
URL: http://196.251.66.20/bins/xnxnxnxnxnxnxnxnmipsxnxn
URL Status:Offline
Host: 196.251.66.20
Date added:2025-11-01 07:33:13 UTC
Last online:2025-11-09 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-11-01 07:34:15 UTC to abuse{at}nybula[dot]com)
Takedown time:8 days, 5 hours, 45 minutes Bad (down since 2025-11-09 13:19:46 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-09n/aelf 20a97ceb23904d38193dc12b4b2926da20b18cd0dcb9d7558394962dfd973cc4n/aMirai
2025-11-03n/aelf f0312ecf7c179b0c6335baa7b7d0aceb363098a12279d484510da04b75f9e98fn/aMirai
2025-11-01n/aelf c076c62c12715350a5314a471dc2082d6dcceee8beb1042238026862cc9f0fd9Virustotal results 12.70%Mirai