URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.253.44/re.bot.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3474306
URL: http://87.120.253.44/re.bot.arm
URL Status:Offline
Host: 87.120.253.44
Date added:2025-03-12 01:32:04 UTC
Last online:2025-03-29 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-03-12 01:33:06 UTC to abuse{at}neterra[dot]net)
Takedown time:17 days, 5 hours, 14 minutes Bad (down since 2025-03-29 06:47:07 UTC)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-16n/aelf 8a85905eb5b36420fa45c0efe0b74bd95542cc4c4ba5a8616f7ff290a51c2b14n/a
2025-03-14n/aelf ed1c92ac64c3d94e3accb9d44054fa1ab24b1219824dfb9e57e789b7729c8039n/a
2025-03-13n/aelf 3ccc0d0ae0fd81dadeeeeb0e03db8e34912e59221e89077b523856996e63cf8fn/a
2025-03-13n/aelf d187c6b5dd1d5b84873f0904ab55fc5f3d2c49c00825d55f1693fa6aa2014aa3n/a
2025-03-12n/aelf 786de3339a1c780eb4a74e7373bd2840b41bbc417518e0708c82ed9af491c87dn/a