URLhaus Database

You are currently viewing the URLhaus database entry for http://mn.34509.su/bins/mao.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3766742
URL: http://mn.34509.su/bins/mao.arm
URL Status:flame Online (spreading malware for 2 months, 5 days, 23 hours, 23 minutes)
Host: mn.34509.su
Date added:2026-01-31 16:55:21 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-04-04 22:34:13 UTC to abuse{at}as49870[dot]net)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-06mao.armelf 3a6bbae2e93670400b2a39e59c16e7fcace3d72a70c319cebd1bf1c858eb9c3fn/aMirai
2026-04-06mao.armelf 19865318517cf7eef0e157c2738f1f4dbf8e844f9440a91cb8dd8b2072be58c5n/aMirai
2026-04-04mao.armelf 73d6959881e86abde6fa3398f8377edc906892297e836d501b01e9e51e5e2131n/aMirai
2026-02-06mao.armelf a98fc17acb6a3a274eb728bc4d87d627eb3d41f37ebefd67b57ac9e896bff1fan/aMirai
2026-02-03mao.armelf 37511f960894bb1bec92f792eb9a772a6a7926596155cbe3f60ca2b81a04e743n/aMirai
2026-01-31mao.armelf 21fd5b0561383fa90237da3d6affa587530664784e39f7e5896efa144c28e679n/aMirai