URLhaus Database

You are currently viewing the URLhaus database entry for http://62.60.159.184/bins/parm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3865876
URL: http://62.60.159.184/bins/parm5
URL Status:flame Online (spreading malware for 4 days, 7 hours, 11 minutes)
Host: 62.60.159.184
Date added:2026-06-17 01:35:14 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-06-17 01:36:10 UTC to abuse{at}netcrafters[dot]host)
Tags:62-60-159-184 elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-21n/aelf b11af840cb0228fbb62786d30397564cd4a45b1d67b9ff1fb9e47bb7012de1acn/aMirai
2026-06-20n/aelf 4d8e51b9e14202926d2ab417a1957f4a46d0009502be35942c47c69e41329729n/aMirai
2026-06-19n/aelf 76e12dbc2b7221386ed324989f50cd5bb15827a4159e7652d68124107c8d44d2n/aMirai
2026-06-19n/aelf a0e3d38ca27ec312b6c97ace7dd3d8fa72f229b6bef1ed60eea86fd002c2afe3n/aMirai
2026-06-18n/aelf 720c93aa7895a26e1c71609b4a17e3930ff1a4a435a035124bfb603b19d95d5bn/aMirai
2026-06-18n/aelf 55b7e3c8f04e3ba7d9bef0b8cc7d605ba57d1c0aa2220e332c5f3602314f3f56n/aMirai
2026-06-17n/aelf a15c5f705a00418f91694c4eca47b07686b006e76ed62cb4174e92b7a387cb79n/aMirai
2026-06-17n/aelf 7d0ee542fdb2b6b4986d14837d479afcb81ee531db65f5b963268f79dc8a81e0n/aMirai