URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.88/arm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740590
URL: http://158.94.210.88/arm/
URL Status:flame Online (spreading malware for 2 days, 2 hours, 59 minutes)
Host: 158.94.210.88
Date added:2025-12-22 21:25:15 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-12-22 21:26:16 UTC to abuse{at}lanedo[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 5c51a8fb6df327e434e3052e1b36d827bba30932bec09d685cfcc793b3305024n/a 
2025-12-24n/aelf 436d60a0eecd879b94cf2bba3683eb8e565e54f58571f00fd80c7d873ef6854fn/aMirai
2025-12-23n/aelf 2dbc0a367b2c2cdc2b44df20086479e71cdcf4ba72114dfd8aec1e3ba9c781c5n/aMirai
2025-12-23n/aelf 10f7594ec5f6930d49e15835c40c1cac0dddca1749f3c0c69d15d7117b5e301an/aMirai
2025-12-22n/aelf 2f1c76efc08060c1f68199bff12060c39b6caacf248729e782974182554c50b6n/a