URLhaus Database

You are currently viewing the URLhaus database entry for http://64.89.163.109/israel.armv5l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3773410
URL: http://64.89.163.109/israel.armv5l
URL Status:Offline
Host: 64.89.163.109
Date added:2026-02-07 04:06:11 UTC
Last online:2026-02-22 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-07 04:07:11 UTC to noc{at}miteflux[dot]co[dot]uk)
Takedown time:15 days, 8 hours, 55 minutes Bad (down since 2026-02-22 13:02:50 UTC)
Tags:arm elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-16n/aelf b5a84485b1cea59cb3005530c77c9245699dd8807e3fb3ff4c05a8f203dcc279n/aMirai
2026-02-15n/aelf 8439c0c3038d03dea121b8cd41ceb2b6c8556ad96891cf418827b741b4020123n/aMirai
2026-02-15n/aelf ae00a052ce855b22d7833328c8629c833fb9531b4ca99490455275b4f5df922fn/aMirai
2026-02-14n/aelf a8eaed04cd9f0e44803791da31b80c0235444138116b1793a8bc8a0ff70ea246n/aMirai
2026-02-14n/aelf a91bba4fe2b1022d32193780a61f08418558f21e6f6e3aeed9b0332b71ec0a65n/aMirai
2026-02-14n/aelf 45ffaaf041247cbfb34845c1ff69fd359618db32508c196f35ea5f874ebab32an/aMirai
2026-02-07n/aelf 7761b788577830645da6f68812b3881132df87b835cc8016abdb27e4c84cd3d8n/aMirai