URLhaus Database

You are currently viewing the URLhaus database entry for http://95.155.151.113/d/xd.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3894050
URL: http://95.155.151.113/d/xd.arm
URL Status:Offline
Host: 95.155.151.113
Date added:2026-07-30 02:38:13 UTC
Last online:2026-08-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-07-30 02:39:19 UTC to report{at}abuseradar[dot]com)
Takedown time:17 days, 12 hours, 15 minutes Bad (down since 2026-08-16 14:54:59 UTC)
Tags:arm elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-08xd.armelf fd0e6eb71c4cd3349b08e529f4b323f1012b4643533ced1dd5de0ccdf9451245n/aMirai
2026-08-07xd.armelf 8528ad198c42b80a0ec5e6c352d61b244ae66ac79b6f97acc5fa53f9ca8dc74cn/aMirai
2026-08-05xd.armelf e7ead284f1a41d07aa97cbf52fd73a25bb79a9787fa1842202a218d86d414718n/aMirai
2026-08-04xd.armelf cdab757d06e9000a4b028e4a0000c5b7594b5a00e600df6eaa8d3cb4ef3acff7n/aMirai
2026-08-02xd.armelf fe4500826280340597344445a1734897495008210740ea41f80f3b5dbc908184n/aMirai
2026-08-02xd.armelf 405ab54e2f2b5f8e2b865ec75e0547ee4aea3a6521402958c18a40b7e8ade432n/aMirai
2026-07-30xd.armelf c18b493bdf0403f015b58745c3ef3b18a7253437fcb567a1e5f63a2887eeaad1n/aMirai