URLhaus Database

You are currently viewing the URLhaus database entry for http://14.225.20.10/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3694303
URL: http://14.225.20.10/arm5
URL Status:Offline
Host: 14.225.20.10
Date added:2025-11-02 18:09:10 UTC
Last online:2026-01-07 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-02 18:10:18 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 months, 6 days, 0 hours, 38 minutes Bad (down since 2026-01-07 18:48:38 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-03n/aelf 1dadc79006e0179905f7aacce2c3700236863cdfb470d57ea1c4147dc8250bb2Virustotal results 32.31%Mirai
2025-11-02n/aelf b0230d8f589080e960652d7338df761d23c8c9eb4062012b5ba633e93a8d52a3Virustotal results 61.67%Mirai