URLhaus Database

You are currently viewing the URLhaus database entry for http://207.244.199.152/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3604491
URL: http://207.244.199.152/arm6
URL Status:Offline
Host: 207.244.199.152
Date added:2025-08-16 08:21:23 UTC
Last online:2025-08-18 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-16 20:04:10 UTC to abuse{at}freakhosting[dot]com,report{at}abuseradar[dot]com)
Takedown time:1 day, 18 hours, 25 minutes Poor (down since 2025-08-18 14:29:31 UTC)
Tags:elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-18n/aelf 61bf662cc38fbd8cf021b4e2eadb5b1170f2cbdd6087d84ed3153af1ab1d754dn/aMirai
2025-08-18n/aelf 9b962a3dc6e351755a06f78796ac62b234b2885e4f9d082c6f54df7280927cd3n/aMirai
2025-08-17n/aelf 19fb3510670e09e2eca92934f83a1ebbd4482fecf35b54e7c7dfffd1775ed39cn/aMirai
2025-08-17n/aelf b2928ca8404c2be98d2c5f3ae3715b1cc16430fec2f3c834dbc2c24ce53e6813Virustotal results 34.38%Mirai
2025-08-16n/aelf 2a879d61896e4bbf305ef71344e309d1fbe09291bb17f1444ca511dec9b50c57n/aMirai
2025-08-16n/aelf 68d5b9f985a462caf224cc8e00bfa32fa041f86188ce478ea014e187f7c9c832Virustotal results 40.62%Mirai