URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.88/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740053
URL: http://158.94.210.88/arm
URL Status:flame Online (spreading malware for 2 days, 12 hours, 9 minutes)
Host: 158.94.210.88
Date added:2025-12-22 09:56:20 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-12-22 09:57:17 UTC to abuse{at}lanedo[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 5c51a8fb6df327e434e3052e1b36d827bba30932bec09d685cfcc793b3305024n/a 
2025-12-24n/aelf 575c3608ca4276cf4df9daf6813d7c17848e75044f59ec2b5bf3c28124a3de81n/aMirai
2025-12-24n/aelf 436d60a0eecd879b94cf2bba3683eb8e565e54f58571f00fd80c7d873ef6854fn/aMirai
2025-12-23n/aelf 2dbc0a367b2c2cdc2b44df20086479e71cdcf4ba72114dfd8aec1e3ba9c781c5n/aMirai
2025-12-23n/aelf 10f7594ec5f6930d49e15835c40c1cac0dddca1749f3c0c69d15d7117b5e301an/aMirai
2025-12-22n/aelf 6e7b7cef1f7a1b7f264047cc4ae0e1d42a96222316119f679c00013fb47df23an/aMirai
2025-12-22n/aelf 88107351b5c7015bd6d46d4f01d4d2dac0733d5eb157801bdbe672a848f10221n/aMirai