URLhaus Database

You are currently viewing the URLhaus database entry for http://154.12.95.211/bins/Mddos.arm64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3696739
URL: http://154.12.95.211/bins/Mddos.arm64
URL Status:Offline
Host: 154.12.95.211
Date added:2025-11-05 04:36:15 UTC
Last online:2025-11-09 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-05 04:37:13 UTC to abuse{at}cogentco[dot]com)
Takedown time:4 days, 0 hours, 47 minutes Bad (down since 2025-11-09 05:25:10 UTC)
Tags:elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-06n/aelf d73cb4e855e7120c78cff153f56c2aaf09ca1948cb236095d70c6e62003e8e0fVirustotal results 15.62%Mirai
2025-11-05n/aelf 2fb27769abe4a38ac26b7940983ac94b180d769c0f3a442ada21e57b4c4377ecn/aMirai
2025-11-05n/aelf afcd9a29fb2dc0c677c8dca15c32829b8f2bafed0d61150ec8d19ba74acdc588Virustotal results 16.13%Mirai
2025-11-05n/aelf 2e6fecefa3062d2306124e014643a14066981f4865dedbeffb8c1d057dc650b2n/aMirai