URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610340
URL: http://109.205.213.5/resgod.arm6
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-24 04:22:11 UTC
Last online:2025-09-09 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: redrabytes
Abuse complaint sent (?): Yes (2025-08-24 04:23:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:15 days, 23 hours, 12 minutes Bad (down since 2025-09-09 03:35:14 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-08n/aelf 46de942f38760912e646e5832eb6dbc8dc128b8f8e20b678de7e2e34c4ea1300n/aMirai
2025-09-07n/aelf c3983172272b258763e184af8cd11e0921dd66844a0c32d0d688fbbb1c2097a6n/aMirai
2025-09-07n/aelf d67ab690e2c1bb16ef4c905dff813783a696da4c9cf5783b0aa6d4467798cbcfn/aMirai
2025-09-06n/aelf bbf3cf4c6c18eae31d2bfd4f869ea941075e30e579c2acf25339693ed7b5fc72Virustotal results 40.62%Mirai
2025-08-26n/aelf 8c91991579bb708c02905056acfdc093f749f4c3e48d88e85fbb5dda29da461en/aMirai
2025-08-24n/aelf 60b7791f101911e4fce435bfcdc037fe76bd3a63dc9f9ea392902ac91e601779n/aMirai
2025-08-24n/aelf 9b8656cd82dcb43ca8639b563d532e514ade93f759c43e4a6fd79851b12bf96fn/aMirai
2025-08-24n/aelf c5fabc2a9780bf7464219eb346851d7eae3fdbe827d1e946be610cd96e32c6ddn/aMirai