URLhaus Database

You are currently viewing the URLhaus database entry for http://216.9.225.23/debug.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3838912
URL: http://216.9.225.23/debug.arm6
URL Status:flame Online (spreading malware for 22 days, 17 hours, 15 minutes)
Host: 216.9.225.23
Date added:2026-05-04 23:10:14 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-05-04 23:11:11 UTC to info{at}whitelabelservices[dot]us)
Tags:arm elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-10n/aelf d039dfa993a7b84d38c63ec1b945b2a16f856e692cd1f2ac26af9f90a81b2b8fn/aMirai
2026-05-09n/aelf fe2acb7abf32bf9464793be09615fbcc824c2339eebb2f5fa235608cb792a242n/aMirai
2026-05-09n/aelf 00cf5fc1adcb4e56c532645274065bfcb6f002d927a33222820464cb9799293dn/aMirai
2026-05-04n/aelf 3f11a37ba1dab0bd9ed5172bb78c1f9353632739b588bafdeba655b49ef9d94an/aMirai