URLhaus Database

You are currently viewing the URLhaus database entry for http://161.248.238.54/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3533609
URL: http://161.248.238.54/arm
URL Status:Offline
Host: 161.248.238.54
Date added:2025-05-03 08:37:07 UTC
Last online:2025-05-14 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-05-03 08:37:30 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:11 days, 2 hours, 45 minutes Bad (down since 2025-05-14 11:22:57 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-05n/aelf 6f6b15d1480dcd4eb3339bfe5210a58694433f7d62fa38b4d4ab729810ec301bn/aMirai
2025-05-04n/aelf b168402e05ed66904af779bf21ab4fcf2c3a8320dec967b1d386e83ca1681878Virustotal results 23.81%Mirai
2025-05-04n/aelf 40d7bbb9be93675e084faa0922cbb2bd2f11f836cf398b5d068afee75a1f6d2cn/aMirai
2025-05-03n/aelf ddeae35a2a8b20daa32258e2b249482952841f4e6d7752dfc9ace10d1bd626aen/aMirai