URLhaus Database

You are currently viewing the URLhaus database entry for http://142.248.80.139/agent_arm64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3832662
URL: http://142.248.80.139/agent_arm64
URL Status:flame Online (spreading malware for 1 day, 17 hours, 32 minutes)
Host: 142.248.80.139
Date added:2026-04-26 22:50:22 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-04-26 22:51:12 UTC to anush{at}advinservers[dot]com,anush{at}fro[dot]email)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-28n/aelf 6691d19f8eb9cd9b6f90fa99af34e74a2e869fc042b7649da80b1a8175276943n/aMirai
2026-04-28n/aelf 3c937ff63c8bffd2aeb78fa788d9e215896393929f42e2f08f80588f60a25af4n/aMirai
2026-04-27n/aelf 3544ea21134e5bf99b6967cd7213a857b9e59ca1b3e8e7f59d5de04ed9f290dan/aMirai
2026-04-27n/aelf eb29ee725c6d9054f6734a2d50b4fff6a7f2c20483787ed916dd4d0e796663d6n/aMirai
2026-04-26n/aelf 232c3f1f4c35cd4ba17bb2f3ac7893f0202eeacb122415dfd90377649c9e230en/aMirai
2026-04-26n/aelf 280978d1639f25d2326b9ca09049dc0567fe863f003c772c2f74e37243f935a4n/aMirai