URLhaus Database

You are currently viewing the URLhaus database entry for http://43.228.157.130/static/ciubuc_arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3816142
URL: http://43.228.157.130/static/ciubuc_arm6
URL Status:flame Online (spreading malware for 4 days, 23 hours, 58 minutes)
Host: 43.228.157.130
Date added:2026-04-11 09:46:21 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-04-11 09:47:12 UTC to admin{at}pointtoserver[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-12n/aelf 669cfe080d1ab5aa8eacdd9401235a291eacd7f9564b94739780b55fc5c22f3dn/aMirai
2026-04-12n/aelf 7ccd8cc0373fdcd489db2db9aeedd1bc4f4033d2a7f0a68f7f848bef8ba45643n/aMirai
2026-04-12n/aelf 34cb1d415bc4a4cb0cfaaee49a95321dd69575b05c4cdd3683b655412a7b61bcn/aMirai
2026-04-11n/aelf 33d062fa3cdb2894325bf5666cde51135fec09440595c90a845e9b9d720c3e07n/aMirai
2026-04-11n/aelf d559dfe71a23dff0cde233d41152355fc4d8450417b8cf4000723c757123c3b8n/aMirai
2026-04-11n/aelf 473612bfc3478efcde5666a2bcb6b5be5f21f56f98b4b64b4524ce682b176ab1n/aMirai
2026-04-11n/aelf 1da50cb8ebf68660ecc61b87ae0d8ffea5646c82aadaf8f9313b993bf087c1ban/aMirai