URLhaus Database

You are currently viewing the URLhaus database entry for http://64.89.163.109/israel.armv7l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3773406
URL: http://64.89.163.109/israel.armv7l
URL Status:Offline
Host: 64.89.163.109
Date added:2026-02-07 04:06:10 UTC
Last online:2026-02-22 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-07 04:07:10 UTC to noc{at}miteflux[dot]co[dot]uk)
Takedown time:15 days, 9 hours, 14 minutes Bad (down since 2026-02-22 13:21:55 UTC)
Tags:arm elf geofenced mirai link Okiru opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-16n/aelf d00603d29b832ddc220ef4b0927c1f2a3436c7bf0d231b1f3c8a1958e4a78757n/aOkiru
2026-02-15n/aelf 8d4ada8db727f3e684fa2f22cdf99610b71898528fce31fbd7267c058d6c5583n/aMirai
2026-02-14n/aelf 996b94e8e54c3642292acdbb70e97d346be5e531ecfbdd5548f788d44d7aa12fn/aMirai
2026-02-14n/aelf 4b77388d287e1544ccfbb7e5feaa4418be3dca60b1d0d54c56d8a7371c2e9a3dn/aMirai
2026-02-07n/aelf 759a02f8124938055fde70fececeffea388002033a58b2a7101902131bdc3425n/aMirai