URLhaus Database

You are currently viewing the URLhaus database entry for http://160.187.146.122/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3494039
URL: http://160.187.146.122/arm
URL Status:flame Online (spreading malware for 1 year, 3 month, 28 days, 14 hours, 13 minutes)
Host: 160.187.146.122
Date added:2025-03-28 21:39:06 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-03-28 21:40:08 UTC to hm-changed{at}vnnic[dot]vn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-14armjson 911708b2be1e4952eaa67bca382511067c2ff288520dfc94995a48653cfe201dn/a 
2025-05-08n/aelf c8b221b3f1fe50842ac45a52fc7217ecdf671d3bfaca51be78c9076923165341n/aMirai
2025-04-27n/aelf 08fee3307d96f3ca94061d28f25fd90d667021b2421dc5a473e828c5c619c970n/aMirai
2025-04-26n/aelf 836e54183a4a4efa7829b760e1287c33f6f129bf37397e007526c44b929535f1n/aMirai
2025-04-16n/aelf c380abfd4409e35664e559bc49a8cb85b77468ca654efe24583968b4a0d61554Virustotal results 45.90%Mirai
2025-04-16n/aelf 9b402ff414cb359e0da66ce80bdd5ac90333f20c3538ac33e7de1d2860959581n/aMirai
2025-03-28n/aelf 3733a7359c6af00ee58fd21a86f5b56feeeea5b0373df26f41ccef8330be42afn/aMirai