URLhaus Database

You are currently viewing the URLhaus database entry for http://162.249.125.147/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3831376
URL: http://162.249.125.147/arm7
URL Status:flame Online (spreading malware for 9 days, 10 hours, 13 minutes)
Host: 162.249.125.147
Date added:2026-04-25 14:35:28 UTC
Threat:Malware download Malware download
Reporter: malwarereport
Abuse complaint sent (?): Yes (2026-04-25 14:36:23 UTC to report{at}zetservers[dot]com)
Tags:mirai link mossadbotnet

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-02n/aelf 34c085e9180b5d76db3014a6c3f8e27fbb1d76e0e42db528721dd9a28f3bcac3n/aMirai
2026-04-26n/aelf d5b9defcb563f5e460b2d7814fe31b35e8389033795b5d690d80b40dcdb84597n/aMirai
2026-04-25n/aelf 61e2779702fbe93e41d2127a7f9a8ed4cd1c22d16e5af1b47c5f73be21b34ff2n/aMirai