URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623624
URL: http://158.94.209.216/arm
URL Status:flame Online (spreading malware for 2 months, 15 days, 20 hours, 50 minutes)
Host: 158.94.209.216
Date added:2025-09-14 09:01:36 UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-14 09:02:21 UTC to support{at}ipv4[dot]global)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 14883298489d57b2242533f561769e8f21737126e8560c4b9955dc701478c23eVirustotal results 18.75%Mirai
2025-09-29n/aelf 4baca2569dba323eba0f6846b5e94fc7b4b2b67b0763ba6cfa49acf20fde161cn/aMirai
2025-09-28n/aelf f4e39a7562166dd760924c331502dbd9ec9f99755b9a4d679b8ff76b69397db8n/aMirai
2025-09-26n/aelf 644aa0423e363cb8b5b0015524eb574b98e775e614ecd6933a73db3074751474n/aMirai
2025-09-25n/aelf d655be3fa5198ab05d2e51e55953b442460f8f95b357b15568ea5cb89f4f529dn/aMirai
2025-09-14n/aelf 86c913791bb43de279ba0ecacbe54a5ba85bfbc96a23824ff9c6fd6644f7def7Virustotal results 15.62%Mirai