URLhaus Database

You are currently viewing the URLhaus database entry for http://160.30.159.104/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3771811
URL: http://160.30.159.104/arm
URL Status:flame Online (spreading malware for 23 days, 14 hours, 20 minutes)
Host: 160.30.159.104
Date added:2026-02-03 21:01:19 UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2026-02-03 21:02:17 UTC to hm-changed{at}vnnic[dot]vn)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-27n/aelf 128bf0790cd11aacb53eaa299d05e4ce2cb02f36e14c52323493b1395e7ad9b0n/aMirai
2026-02-09n/aelf 175b39d1072e1ceb5d44af99d814f6278978c923ebdfdd03072cd228ed906505n/aMirai
2026-02-07n/aelf 7e5d1966724b50152f30d5ad1c0149af47e801170f2f811dfc4d34c7f5bc1593n/aMirai
2026-02-06n/aelf 785f25a0a7f303eb5bd979b85fbcd1196fa6dd66279aab6f8ade6673c8d1e162n/aMirai
2026-02-06n/aelf e545105c549778ad247be60f5e1d8a6a248e03d90ad7e58f811fb06bd4dfa7d6n/aMirai
2026-02-03n/aelf 7a793df0a54a8e866f9eae27d506ab41bdadceb3a1f09b1a79a1a50be6cdd8ebn/aMirai