URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.107.133/bins/parm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3791143
URL: http://196.251.107.133/bins/parm
URL Status:flame Online (spreading malware for 1 month, 26 days, 18 hours, 55 minutes)
Host: 196.251.107.133
Date added:2026-03-07 00:02:21 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-03-07 00:03:15 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-18n/aelf 064fc04504e868ec0f453d426b77a25fdeaeda9abb9dc72ec5dcede19bdf157fn/aMirai
2026-04-17n/aelf 95ec7739d50ac227f17a4214a57f2b9093a57f61a52a05cdf2681be13f595e1bn/aMirai
2026-04-15n/aelf fc38381eae0370afab4933713374775157e96f6921e126f8b71f10ed89cbc5b3n/aMirai
2026-04-14n/aelf 4a3b082d323b6ea17e4a9f2f021874c402b65a84c92f852fa6c0ba7210eb2cd7n/aMirai
2026-03-07n/aelf 858d9659183cb8eaea14a8a391ef319cd723f1b6e5dba04adbfb799c8e3bbd73n/aMirai