URLhaus Database

You are currently viewing the URLhaus database entry for http://185.244.36.200/arm7?ddos which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2896136
URL: http://185.244.36.200/arm7?ddos
URL Status:Offline
Host: 185.244.36.200
Date added:2024-06-18 21:29:04 UTC
Last online:2024-06-23 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2024-06-18 21:30:14 UTC to abuse{at}spectraip[dot]nl)
Takedown time:4 days, 23 hours, 40 minutes Bad (down since 2024-06-23 21:10:30 UTC)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-06-23n/aelf 87a3fff1105af03dfa6d36b15fca1f8d0c7950f53dd5f14c277af01d0a2f960en/aMirai
2024-06-23n/aelf 78050027dc1bfef0c79d420c3cc7957965450775c487302baf57ab70d95c9fc5n/aMirai
2024-06-18n/aelf 682895d669c00cb40171dccf95804c26d0f621003a1cc92425285ca42d385ae7Virustotal results 16.67%Mirai