URLhaus Database

You are currently viewing the URLhaus database entry for http://62.197.136.92/shitnet//irc.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252962
URL: http://62.197.136.92/shitnet//irc.arm6
URL Status:Offline
Host: 62.197.136.92
Date added:2022-07-01 09:40:04 UTC
Last online:2022-07-13 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2022-07-01 09:41:04 UTC to abuse{at}serverion[dot]com)
Takedown time:11 days, 15 hours, 4 minutes Bad (down since 2022-07-13 00:45:16 UTC)
Tags:ddos mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-07n/aelf 630b0bcbed5029ecb7238ea6fdc14c29f791c5e1dc37a235a5779b90818dbe1en/a 
2022-07-07n/aelf 7e54284e55f33e7792614d7f33300320254ed005cb5f0444d3d8b6c62164b812n/a 
2022-07-07n/aelf 8b6e76cabe313fc514ce2f80563537f403f1c34c5d44799dc1c842f9c356592eVirustotal results 35.00% 
2022-07-03n/aelf ba378c637cb785ab7e79b4856f525a5fe8cc556a4644a7767baf71002b752a11Virustotal results 31.67%Mirai
2022-07-01n/aelf 377582133b4389f7679f49c9940ffb05bc6a21113baa2b88cbeee12a049c1078Virustotal results 33.90%Mirai