🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://31.77.227.121/bins/parm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3902563
URL: http://31.77.227.121/bins/parm5
URL Status:Offline
Host: 31.77.227.121
Date added:2026-08-12 05:23:17 UTC
Last online:2026-08-19 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-08-12 05:24:17 UTC to abuse{at}rocket-cloud[dot]org)
Takedown time:7 days, 9 hours, 58 minutes Bad (down since 2026-08-19 15:22:51 UTC)
Tags:arm elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-19n/aelf 0ab998bc66862882cf5a416e4f568b99fda4e823e34d4e0347966d3881cdd7c1n/aMirai
2026-08-15n/aelf 376c342dc4261ca7ab791d1830696d3b0401dba1210a4386d8e58f63cbd5aa97n/aMirai
2026-08-14n/aelf 98195afa618f125b12038f2b703f4c01f470d539475115e64e15996db025a9f9n/aMirai
2026-08-14n/aelf 71a56c16e88c9bef1178312e727b68050628af02ff3d2789a62953c4cd8d352en/aMirai
2026-08-13n/aelf 42bf11ac8f367f6689495240ead88b8900c9acd67a0557371953511df7355a8bn/aMirai
2026-08-13n/aelf 6b9726c40810214f4c9991fd472060ee540ed6fc6df98c1bcc47048802240bedn/aMirai
2026-08-12n/aelf 61946ef9553c3be03ba21df09f906e66a6e2c30e88cab1c290bcac83dc5bb451n/aMirai