URLhaus Database

You are currently viewing the URLhaus database entry for http://31.56.209.125/bins/m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3838004
URL: http://31.56.209.125/bins/m68k
URL Status:flame Online (spreading malware for 3 days, 20 hours, 25 minutes)
Host: 31.56.209.125
Date added:2026-05-03 21:25:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-05-03 21:26:13 UTC to abuse{at}swissnetwork[dot]io)
Tags:elf m68k mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-06n/aelf 5e22a5f4d5f24793a92b45598967b83d3bfe8c3cf8a53bbb6203ace43ddefde7n/aMirai
2026-05-06n/aelf 73405a9de316fb93d5dda768817f448d197f93f5c49eae84c5290cae1f456b37n/aMirai
2026-05-04n/aelf b5ec7e4729fdd2e425fa07cdcf60c33fe9a5ae617113c773c5a4691afc798400n/aMirai
2026-05-03n/aelf a8526e4caf12c8c19ba19a568b390d7a1d6ff17e18628a68c6187c14f5edb12bn/aMirai