URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.159/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3598076
URL: http://213.209.150.159/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arc
URL Status:Offline
Host: 213.209.150.159
Date added:2025-08-07 07:31:08 UTC
Last online:2025-09-15 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-07 07:32:10 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 9 days, 2 hours, 28 minutes Bad (down since 2025-09-15 10:01:08 UTC)
Tags:arc elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-03db0fa4b8db0333367e9bda3ab68b8042.archtml 00be7f643a12ac2221c9ba8df4fb34b3701c336fa830d24fe906c55364ef7b35Virustotal results 22.58%
2025-08-23db0fa4b8db0333367e9bda3ab68b8042.arcelf 248b6599aebc4e053a68ae502bafc1fec19cc1edcc455a8358e2d3dbe46f0e5en/aMirai
2025-08-22db0fa4b8db0333367e9bda3ab68b8042.archtml e480c5556efd90bf1c71eb9a645ad1c7c31b2610f68aec7ac57a28218446484cVirustotal results 21.67%
2025-08-20db0fa4b8db0333367e9bda3ab68b8042.arcelf 2aaafa22fb6b7eb4b6dc9badd15ce23026079ade1db36e0ba1083f01f8a529f5n/aMirai
2025-08-07db0fa4b8db0333367e9bda3ab68b8042.arcelf 1c348e6bb0cd3183a84bbd00cb0d0b231dd40e60218cde61b5618c92f63c0e4cVirustotal results 62.50%Mirai