URLhaus Database

You are currently viewing the URLhaus database entry for http://89.169.35.229/bot.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3579797
URL: http://89.169.35.229/bot.arm6
URL Status:Offline
Host: 89.169.35.229
Date added:2025-07-09 18:46:14 UTC
Last online:2025-07-13 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-09 18:47:10 UTC to abuse{at}aeza[dot]net)
Takedown time:3 days, 6 hours, 18 minutes Bad (down since 2025-07-13 01:06:01 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-11n/aelf 196c5d29e89d7985827ee4118cb6ab530a4d7419719bfd4d220a2c743ce4fac8Virustotal results 51.67%Mirai
2025-07-11n/aelf b6dac4f296b8601353ed5a06b305a44baae6eccd8eb36816070a1a102c4d3f68n/aMirai
2025-07-11n/aelf 8d7c8a649ca99a526e4eafc72a73c7008976d69832c73d7d6405d8cb634d724fn/aMirai
2025-07-10n/aelf 65e8430e9f43e980bea657f6066136e1b8079c3623886f297b38f5e86c800955n/aMirai
2025-07-09n/aelf 4fd1fda8ddb710faae7902a81219186aad24f0f25a9f124ad566c877205a2aafVirustotal results 67.19%Mirai