URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623693
URL: http://158.94.209.216/arm5
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:13 UTC to support{at}ipv4[dot]global)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 82ee72be70e8dce122910449268514083943892258ea9b9d21068e03286d03f8n/aMirai
2025-09-29n/aelf 5fded566e53c7ea818103812ec1e95430167608e0908e26a26c18bc8c11f9a7an/aMirai
2025-09-28n/aelf 787ed7dd6b11f98efc980496fb125cc6e9284f1bc94cd827d0a0215ea16f114cn/aMirai
2025-09-26n/aelf 6abd0e768d4be97506f43d95d8c8e2046da9ce21c35de4f670e588b90e867698n/aMirai
2025-09-25n/aelf 5de30d81c38b09cd258b4a8f0ce1a23d5dcb2ed2b17bd4143059fd71c154ac01n/aMirai
2025-09-14n/aelf 668089cf4e3edc2060b1d60fb6dd3aa35f78518ab6b272fdac3c361953c7c17dVirustotal results 33.87%Mirai