URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.88/00101010101001/S3o.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3712140
URL: http://41.216.189.88/00101010101001/S3o.arc
URL Status:flame Online (spreading malware for 2 days, 9 hours, 14 minutes)
Host: 41.216.189.88
Date added:2025-11-19 21:59:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-19 22:00:16 UTC to abusepoc{at}afrinic[dot]net)
Tags:arc elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-21S3o.arcelf 153678cf354711103145179d675015b5e3f077e771dd997cc2cddecc81c92f46Virustotal results 56.92%Mirai
2025-11-21S3o.arcelf 3be292e49b1212cd4ce8fb1f63509544dec1688931d35c7df4c67dd95f9ca675Virustotal results 56.92%Mirai
2025-11-20S3o.arcelf dcbe68064b929e8d7c085f7feede224ae699187818eb4db82bb38f2399abbbc5n/aMirai
2025-11-19S3o.arcelf 5f5a706a8a71a3c575a9df6a3e8d1ba9675be972aa4c03b691a91c936a6ee1fdVirustotal results 54.69%Mirai