URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.107.133/bins/parm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3791146
URL: http://196.251.107.133/bins/parm5
URL Status:flame Online (spreading malware for 1 month, 22 days, 6 hours, 30 minutes)
Host: 196.251.107.133
Date added:2026-03-07 00:03:17 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-03-07 00:04:12 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-18n/aelf 16aca11323d8bb11a76352e9385a808925492c0e06d4fa9b240f4a130e1e85c3n/aMirai
2026-04-17n/aelf 60571e1f388461f7f630e289f78a1f77fb74fd4fbd01064c2b8af8b3aa96c4fcn/aMirai
2026-04-17n/aelf cdb7c52b80531663b1065f7b4a27606d0f06f58d97464f9f15d766ede8ed942cn/aMirai
2026-04-15n/aelf d9e3cfe175d2d8f0debb67a203d5f7d231983e75cf95f5a4862bf105b0d45040n/aMirai
2026-04-14n/aelf 89cb94076cb120d788a9d7178bfde969a30856f1683d1f1953b97383645efd48n/aMirai
2026-03-07n/aelf a6d8c472a507c244e06a73fe1e8003615cb034f1cee6cc74cac7438ef3403ec8n/aMirai