URLhaus Database

You are currently viewing the URLhaus database entry for http://mywebh.kro.kr/bins/navo.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3550867
URL: http://mywebh.kro.kr/bins/navo.arm
URL Status:Offline
Host: mywebh.kro.kr
Date added:2025-05-23 14:36:05 UTC
Last online:2025-05-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-23 23:30:10 UTC to abuse{at}deluxhost[dot]net,report{at}abuseradar[dot]com)
Takedown time:20 days, 1 hours, 15 minutes Bad (down since 2025-06-12 15:52:32 UTC)
Tags:botnetdomain censys elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-01navo.armelf 09befe06e046e0ff65a4a479cfaf1b5eed92eebbe49e8d484bcd870e26d05a37n/aMirai
2025-05-30navo.armelf 7bf8e9eede05820d14c76e0ae222a8c85559c0be87383ab78c5b8a422044af2fVirustotal results 42.19%Mirai
2025-05-23navo.armelf c3c2ed4c2a13f3244b9ad4f21816703bb5bddb7aa8505888c838c2a7eece9dbeVirustotal results 67.19%Mirai