URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.27/bins/parm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740583
URL: http://158.94.208.27/bins/parm6
URL Status:Offline
Host: 158.94.208.27
Date added:2025-12-22 21:24:17 UTC
Last online:2026-01-10 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-12-22 21:25:26 UTC to abuse{at}lanedo[dot]net)
Takedown time:18 days, 21 hours, 33 minutes Bad (down since 2026-01-10 18:58:39 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-10n/aelf b5ecd9986333d5dbf1e62c879bf196676deb09fc40c1e55ae641210cad53d978n/aMirai
2026-01-09n/aelf c8a1512e9f22f426ebafcea9c1ee3e09f0b1d88bc1049bfe6c308347dd282228n/aMirai
2026-01-03n/aelf 9094de5be92f576714964acc02d13a91a68c814057560adf46d81866965ac872n/aMirai
2026-01-01n/aelf 826981eef0c71c0be37880ea6a078ca9792d655bd49e23a9f3ac4f62bf6f0e87n/aMirai
2025-12-22n/aelf 17ede602f86ad63121865c2d917876bdccb2d8be9075b9d57c0d627fca1321c4n/aMirai