URLhaus Database

You are currently viewing the URLhaus database entry for http://151.243.213.208/bins/navo.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3551138
URL: http://151.243.213.208/bins/navo.arm
URL Status:Offline
Host: 151.243.213.208
Date added:2025-05-23 20:35:05 UTC
Last online:2025-06-12 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-23 20:36:06 UTC to abuse{at}deluxhost[dot]net,report{at}abuseradar[dot]com)
Takedown time:19 days, 18 hours, 55 minutes Bad (down since 2025-06-12 15:32:03 UTC)
Tags:censys elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-01navo.armelf 09befe06e046e0ff65a4a479cfaf1b5eed92eebbe49e8d484bcd870e26d05a37Virustotal results 42.19%Mirai
2025-05-30navo.armelf 7bf8e9eede05820d14c76e0ae222a8c85559c0be87383ab78c5b8a422044af2fn/aMirai
2025-05-23navo.armelf c3c2ed4c2a13f3244b9ad4f21816703bb5bddb7aa8505888c838c2a7eece9dbeVirustotal results 67.19%Mirai