URLhaus Database

You are currently viewing the URLhaus database entry for http://mirailoversddos.duckdns.org/Orbt/Orbt.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3684961
URL: http://mirailoversddos.duckdns.org/Orbt/Orbt.arm6
URL Status:Offline
Host: mirailoversddos.duckdns.org
Date added:2025-10-23 17:37:08 UTC
Last online:2026-01-20 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-01-19 23:09:09 UTC to report{at}abuseradar[dot]com)
Takedown time:2 months, 28 days, 15 hours, 34 minutes Bad (down since 2026-01-20 09:12:59 UTC)
Tags:botnetdomain mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-19n/aelf 18e990cff5095961384325b58d35144084aa56365acbdf6625f662d0d771d476n/aMirai
2025-10-28n/aelf 56bc93c42245723780b706d193f7f1a3a2c46d4665c333f22bf9c58116b9cd18Virustotal results 40.62%Mirai
2025-10-26n/aelf be952d709848255e1c14c70377bffec1f9bbc9d5546f333ffac521fb121cfd98Virustotal results 36.92%Mirai
2025-10-24n/aelf 1813be63e18d00dd54d6512a3386918eb22385f4a522b31d07ea67265d9c53e8n/aMirai
2025-10-23n/aelf 1a35fc9d609a38aac54abc4b035168415f72563f1cb2a47cfd3b98a2286289f3Virustotal results 38.46%Mirai