URLhaus Database

You are currently viewing the URLhaus database entry for http://113.30.152.240/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3778340
URL: http://113.30.152.240/arm5
URL Status:flame Online (spreading malware for 1 day, 12 hours, 59 minutes)
Host: 113.30.152.240
Date added:2026-02-15 14:55:15 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-02-15 14:56:11 UTC to abuse{at}globconnex[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-17n/aelf 2bdc4103f68ce6dee71c46dd8ea44051f820e5bbf14fbc6f929bd6307cbdcc3cn/aMirai
2026-02-16n/aelf 884cfce6639aef2af9ea3dabeabdac283d46e96d00a1bb660bc2a5aab8969f40n/aMirai
2026-02-16n/aelf a1c0688868325690a83d52ae087dd6b422000e1106f9fa9c081ccf65d187748bn/aMirai
2026-02-15n/aelf 2b762725fe032315fdb8e3ac2451060dad259e175be86dea340228ec57377e11n/aMirai