URLhaus Database

You are currently viewing the URLhaus database entry for http://89.32.41.16/bins/parm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3840538
URL: http://89.32.41.16/bins/parm
URL Status:flame Online (spreading malware for 2 months, 15 days, 1 hours, 46 minutes)
Host: 89.32.41.16
Date added:2026-05-06 15:35:19 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-05-06 15:36:13 UTC to abuse{at}hostmaze[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-20n/aelf 826a786afce30c67495d60799ae38d1604bea4732476253a3aab81e1dd5d44f0n/aMirai
2026-06-18n/aelf 96c6c63bb5e198fe4e43749676261fcaaca39df5a8e6e6e31f311f790513b761n/aMirai
2026-06-16n/aelf 1153960865c4456a6ae71cade2b29ea8cfa586c280b2ada2e994d7e72e432b9bn/aMirai
2026-06-16n/aelf e757b5d4b666dc19a042911da0620e0129b9a127ab92af1a2c6f186179ab3bcan/aMirai
2026-06-09n/aelf 85a4b1ae3ad71c491ad162e6ca992667c0656357d4806a240d4e2b3bb4b4163an/aMirai
2026-05-07n/aelf 5e30e4677b2b91eb0b57a646a14bd4fcbe8538967d44598347c7b157ee4f9115n/aMirai
2026-05-06n/aelf 7ce8763895b52c9345961d321a95c1b2dfec59c24dd30873c9ebe191af1fd15an/aMirai