URLhaus Database

You are currently viewing the URLhaus database entry for http://207.244.199.152/arm6nlk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3604505
URL: http://207.244.199.152/arm6nlk
URL Status:Offline
Host: 207.244.199.152
Date added:2025-08-16 08:22:41 UTC
Last online:2025-08-18 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-16 20:04:10 UTC to abuse{at}freakhosting[dot]com,report{at}abuseradar[dot]com)
Takedown time:1 day, 14 hours, 10 minutes Poor (down since 2025-08-18 10:15:07 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-18n/aelf 61bf662cc38fbd8cf021b4e2eadb5b1170f2cbdd6087d84ed3153af1ab1d754dn/aMirai
2025-08-18n/aelf 74b9afd46ea0d6018bec770f68ac87e4e28e36c4927488af3df252ff1d460770n/aMirai
2025-08-18n/aelf 9b962a3dc6e351755a06f78796ac62b234b2885e4f9d082c6f54df7280927cd3Virustotal results 34.38%Mirai
2025-08-17n/aelf 5c30440c516f6048031967a5a62e95946e8a92b9f571e10f0a57d5c4ac0445cen/aMirai
2025-08-17n/aelf 1104ac8e7324f17ab1c108632e55ac569dad54ad273fb0ac8347f7f692250c3bn/aMirai
2025-08-16n/aelf a418961c49037a1f9f97b35944e6659eb43aaa37c5bd81aaa96628f03d3e7b61n/aMirai