URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.152.84/sdxkzX_UXA229x.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3742993
URL: http://192.227.152.84/sdxkzX_UXA229x.arm7
URL Status:flame Online (spreading malware for 18 days, 5 hours, 13 minutes)
Host: 192.227.152.84
Date added:2025-12-25 03:59:07 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-12-25 04:54:12 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11n/aelf f52ee4641fa9d67794922873d98e481346201ac5794340ce9082194bc373550an/aMirai
2025-12-27n/aelf 9c3d107ec8752a58e9b02a0f25fedee5ce88e738863263d8921a492187ba945an/aMirai
2025-12-25n/aelf 4b00c9ff1eb55bd1ab7e067a274dc00a16fd07870f915cbc871e887f16d0277dn/aMirai