URLhaus Database

You are currently viewing the URLhaus database entry for http://www.srv892825.hstgr.cloud/systemcl/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3724825
URL: http://www.srv892825.hstgr.cloud/systemcl/arm5
URL Status:Offline
Host: www.srv892825.hstgr.cloud
Date added:2025-12-04 06:43:16 UTC
Last online:2026-01-23 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-04 06:44:16 UTC to abuse{at}hostinger[dot]com)
Takedown time:1 month, 20 days, 2 hours, 19 minutes Bad (down since 2026-01-23 09:03:47 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-20n/aelf 58979f8f088f4a7ccb290972f63908b9f2aed2745965edec68713c3cd48288ddn/aMirai
2025-12-19n/aelf 68b3c7537cd59c58b64fbf3b20296a0dc41cc0a7198fd387845025751f9ba23en/aMirai
2025-12-13n/aelf 6a06ed6a3ed3f8b63bcc01077ea822334e792687a338357c02eec258417f31bbn/aMirai
2025-12-04n/aelf 08ae005f1cc8abd47effeed2e97daaac8b10070fe9354ec6c04f7702df416686n/aMirai
2025-12-04n/aelf 80d4fa148408c15cab91f173d94d4ab2322ef02c5b9b5dce2778837e182f7f82n/aMirai