URLhaus Database

You are currently viewing the URLhaus database entry for http://185.196.41.180/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3785048
URL: http://185.196.41.180/arm
URL Status:flame Online (spreading malware for 22 days, 17 hours, 22 minutes)
Host: 185.196.41.180
Date added:2026-02-24 16:17:08 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-02-24 16:18:13 UTC to abuse{at}vdska[dot]online)
Tags:gafgyt link mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-18n/aelf 52dd7821809a226cb3b6a3e17ad9dd4833872b950882ef4c4b2fe0e3ca8f296an/aGafgyt
2026-03-17n/aelf 72238d81a1373eb101a1ca9c1e45d977c58056ce6e0719cbdd8517e061e61c7fn/aGafgyt
2026-03-13n/aelf 7033d65fa55d6b8092d4ab9f36efd7a3bff7d70b2cdbd25b7fcf86588cc47395n/aGafgyt
2026-03-11n/aelf 80551c87db15d794c02974165e9a6086a5239f820831042e5573d49a26de9227n/aMirai
2026-03-11n/aelf 864ca68163ef7993f96808f68d18c7d5fa828349bc33da218ac5ead88da98eb4n/aMirai
2026-03-10n/aelf 98a0bbcbe417481e48ddde7653ca2dce48e1ab190e94a893ac1bee08530b49b6n/aMirai
2026-03-10n/aelf ad5255fb2c4b8a29c47b0153d02400c59849b66496d2f5af44bebb9346238423n/aMirai
2026-03-07n/aelf 7a3267f244ea2a3edaee6b4016e7a9e6e6573ac786b56e70114819c351590dddn/aMirai
2026-03-06n/aelf f1566911f42bf94e814c386594e7f709bac8c93436043eb4152060ffe2ef8f08n/aMirai
2026-03-03n/aelf 7ffd25afb89705b96ecee7716eff0900e3d7127b7552db3aac5ea6d983b88607n/aMirai
2026-02-25n/aelf 10f635da68cf55e01a3e82882c2fb2502c6ec800f608b5ac04f5b76c70981e8bn/aMirai
2026-02-24n/aelf fe7f47c1447e9d48014ef6c1853b06c94554b2f93185ad5e0a94d2da7086222en/aMirai