URLhaus Database

You are currently viewing the URLhaus database entry for http://207.244.199.152/arm5nlk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3604503
URL: http://207.244.199.152/arm5nlk
URL Status:Offline
Host: 207.244.199.152
Date added:2025-08-16 08:22:33 UTC
Last online:2025-08-18 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-16 20:03:11 UTC to abuse{at}freakhosting[dot]com,report{at}abuseradar[dot]com)
Takedown time:1 day, 13 hours, 57 minutes Poor (down since 2025-08-18 10:01:00 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-18n/aelf 3c6d883136783d01fbeff4a1e565c2a466afda20ef9af50a33411c45727b0e0dn/aMirai
2025-08-18n/aelf ed10de6f39f2ab7a718f32e2a5b1219e1b6cda776097ea076ea8ce4ee18ca224n/aMirai
2025-08-17n/aelf 125c8ca8790e47a3cc38942853130deca3706de0811e42f072eaf79c54e81bffn/aMirai
2025-08-17n/aelf 75b4a375224b1eed3df177c3183ef10525e8e8bc005cd59fbe7d237898ebdd86n/aMirai
2025-08-17n/aelf 530ca83e464c284667c5209d08aee93c7fc2d63093047c65d6e0826a5dfce96dn/aMirai
2025-08-16n/aelf 631d0896e0d66399cec526d6c4196511ed530285a78064598edbf0af15edecf3n/aMirai
2025-08-16n/aelf 8258900a8cc40c4669f1c0b238afec1e48401305995b0a788a148ac70d9627dan/aMirai