URLhaus Database

You are currently viewing the URLhaus database entry for http://103.149.252.178/bot.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3568118
URL: http://103.149.252.178/bot.arm6
URL Status:Offline
Host: 103.149.252.178
Date added:2025-06-19 05:56:11 UTC
Last online:2025-06-29 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: xqtsmvjnxuurv
Abuse complaint sent (?): Yes (2025-06-19 05:57:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 days, 10 hours, 49 minutes Bad (down since 2025-06-29 16:46:31 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-27n/aelf 61f1709d5d81bc6a521d005312751b7cfa5e5efa4a87b36c78d1df6a56166243Virustotal results 59.38%Mirai
2025-06-24n/aelf 3d96d47e8d629b126f91b8c8aab179aeeb0d8be466b1bae9972395dd34c6e5d8n/aMirai
2025-06-19n/aelf 9c993ebd44da35d5687a37553ec2aa45a76c06e96f4ab50e8e64dc455cd7c088Virustotal results 59.38%Mirai