URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610282
URL: http://109.205.213.5/resgod.arm
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-23 23:33:13 UTC
Last online:2025-09-09 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-08-23 23:34:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:16 days, 2 hours, 15 minutes Bad (down since 2025-09-09 01:49:32 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-07resgod.armelf 6139cadea1690b3f429e693688a7c024b596d373d592ee6d2e7edb77bc436fe2n/aMirai
2025-09-07resgod.armelf 3eba6b39f303e2f83641747365ff9ee8874523cd308fadb15be7ff124d615427n/aMirai
2025-09-06resgod.armelf c9b361b87a061517d7551cd79f350290a8e8d857995cb1944eadca7605ac238fVirustotal results 42.19%Mirai
2025-08-26resgod.armelf a61cf7bcf9faf4e599c133ff6424929ab21707fcd73d9e47a04269998110bf96n/aMirai
2025-08-24resgod.armelf 10a470e361e841768347ecde1c0732fd914965b7277c1aa9b7e1fa1f76b68342n/aMirai
2025-08-24resgod.armelf c749bbd84d9ba5dd9f843e2ef48444c5b4fd4e34e0d24212c08bfc43a3cec17fn/aMirai
2025-08-24resgod.armelf 490a9b4125c2efeb3e691e8989ae7c24c8c7fb10c4ef4426dcc0a1fc107a0c15n/aMirai
2025-08-23resgod.armelf 201cf10b7a8dd23be5926fc167da2f2848c6d916843277cef1e4cb7ee527777eVirustotal results 46.03%Mirai