URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.242.241/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3657687
URL: http://91.92.242.241/arm5
URL Status:Offline
Host: 91.92.242.241
Date added:2025-10-05 13:50:16 UTC
Last online:2025-11-03 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-10-05 13:51:18 UTC to abuse{at}metaspinner[dot]net)
Takedown time:28 days, 10 hours, 28 minutes Bad (down since 2025-11-03 00:19:52 UTC)
Tags:DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-01n/aelf b04ae21ded94c204e1ca235671012a46e3d4dea9d57e961b05d422640e909cfdn/aMirai
2025-10-21n/aelf 579e089eaaf89f5b71ed6ac59bb8a5423639d8dac5d639c0aa1fadbefb58cc65n/aMirai
2025-10-20n/aelf 3ce51ac25d234352da66d815edc94b59d3b43939b0a5d6d8f04da50a6af766c8n/aMirai
2025-10-17n/aelf 49ed53f2194baefadcd6a15add39f5d002214d87cab8b45c9a1b70146ae84508n/aMirai
2025-10-16n/aelf 4e8ab7b52bb0be66456ee7f084c18b35106080c46f5cbd4e7816469c0441a0daVirustotal results 37.50%Mirai
2025-10-16n/aelf 4a60f524366bc7cb5632ad4d281f16459878e6e91b567cc70d11a5467639199dn/aMirai
2025-10-15n/aelf a22ef8b45064184cfa909ac79fdcebcaffa094c2e7a66f9a1e3a9cc3d9b77cd1n/aMirai
2025-10-12n/aelf 02fefccc38005e191335227e183d17f94cad10e9b77184b6925f0abd75a7a39dn/aMirai
2025-10-12n/aelf 85c9cc55cafbf6acb1d359afc6816e41242ad35d5998fe1fcbb23496c9ac1fa7n/aMirai
2025-10-10n/aelf 55eeac7b6f5cc7d57d3d985f0ce59d0b7b25419c03f107779f3b97bfd7f4d9b4n/aMirai
2025-10-05n/aelf 4a5a13b482deb8c51fa9a4412536ce922afba2728a455158742c2deb35de65c7n/aMirai