URLhaus Database

You are currently viewing the URLhaus database entry for http://142.248.80.139/agent_armv7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3832659
URL: http://142.248.80.139/agent_armv7
URL Status:flame Online (spreading malware for 3 days, 9 hours, 28 minutes)
Host: 142.248.80.139
Date added:2026-04-26 22:50:21 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-04-26 22:51:12 UTC to anush{at}advinservers[dot]com,anush{at}fro[dot]email)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-28n/aelf 1c2031fda743220e3a25a683e7452604635c81f29035a3c32f68a34c346936ddn/aMirai
2026-04-28n/aelf a04a4381b6d28196c6c937434e318e91f856cc74ecb661def5de97760a47e761n/aMirai
2026-04-28n/aelf 758d1860087e8ed04a20e639d49dafe60bc01bec4680bdd9309cdebeeb6aecebn/aMirai
2026-04-27n/aelf d0aa34b8e35bf884edbe5e92cb733e38c0f9c9c7e2d77a9d979bc24e5c751b94n/aMirai
2026-04-26n/aelf ef696081f75de76624c19d26955850a91ef7b8c1c21d82af74cadda188dac683n/aMirai
2026-04-26n/aelf 260a0c698f5394094a3ffd7c4bef947a67e1fdc0ea1ec23f4896e5af4ac58c28n/aMirai