URLhaus Database

You are currently viewing the URLhaus database entry for http://report.504.su/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3742442
URL: http://report.504.su/arm
URL Status:flame Online (spreading malware for 21 days, 11 hours, 53 minutes)
Host: report.504.su
Date added:2025-12-24 13:36:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-24 13:37:17 UTC to abuse{at}lanedo[dot]net)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-14n/aelf efea0c3dd7ab6ec84063794b8df7366af33bc495fbca2bdc3ada0ec831f4347an/aMirai
2026-01-14n/aelf 1d2bb74b8c6ef5c7615d279489799ade26d9f6ea17a2fed1d915846f1c140a80n/aMirai
2026-01-02n/aelf 76733fa1268ea8d1d65ee034e702f8ff8e6669e71031287612342414e60da76en/aMirai
2026-01-01n/aelf 80527aadc0101c359a3681060c3b9dff483b8aaaf3521f811f73e949bb7eb163n/aMirai
2025-12-31n/aelf 954fff1e23a4a34df8b3d8cfc2e8c6f74062f341a28c8ebe921f4e6a0aab7e3cn/aMirai
2025-12-30n/aelf de365196b458c300e778524226d038672111443196eaf2c5a5c06cdb1c2c89a9n/aMirai
2025-12-29n/aelf 2b800b162417044f93451ae3710239cf108d12ade41088ca07798b20df8f549cn/aMirai
2025-12-29n/aelf ea93b041f61c4841a1babb8074c9705eb80bddeefb435f5bdc6c8624a0d3bac6n/a 
2025-12-29n/aelf ca3312ba5477812735c1f5d485e66df6d1a5f7137107da071f74f0dbebb03ff7n/aMirai
2025-12-24n/aelf ee673621c3dbacbd95cb472cac37748f699608332c56a63b08500e2d0caeb566n/aMirai
2025-12-24n/aelf 5c51a8fb6df327e434e3052e1b36d827bba30932bec09d685cfcc793b3305024n/a