URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.100.22/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3713969
URL: http://196.251.100.22/arm7
URL Status:Offline
Host: 196.251.100.22
Date added:2025-11-22 12:11:12 UTC
Last online:2025-12-04 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-22 12:12:17 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:11 days, 15 hours, 58 minutes Bad (down since 2025-12-04 04:10:56 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-03n/aelf 547d1e75421bbbfe0492e2191417ad070d3e1e40db837e9aa4737c7946cd67b7Virustotal results 43.75%Mirai
2025-11-28n/aelf 21c9e1189e8447ddb5e233401d47ac4be0321d988e081a75a074d4414cf1a5a8Virustotal results 34.38%Mirai
2025-11-28n/aelf 57b7976fa1baaa51bfb733d5c47ba992923c3e527a9bc9cd625180ad7c11b888Virustotal results 32.81%Mirai
2025-11-23n/aelf 0feffdb13c3bce429c074cf1b5d10a33001b34a4e21d014d5f5151a9d01283f6n/aMirai
2025-11-22n/aelf ca4bd50228d92ac1266506b2ac7fb5636638bd6f3e8ae710fc373c41189ada26Virustotal results 59.38%Mirai