URLhaus Database

You are currently viewing the URLhaus database entry for http://disrupt.anondns.net/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3859712
URL: http://disrupt.anondns.net/arm5
URL Status:Offline
Host: disrupt.anondns.net
Date added:2026-06-06 10:55:09 UTC
Last online:2026-06-13 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-06-06 10:56:11 UTC to abuse{at}ghostnet[dot]de)
Takedown time:6 days, 16 hours, 14 minutes Bad (down since 2026-06-13 03:10:45 UTC)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-12n/aelf 399df624c1a46725a00c61ac737b8f80e1241f71cb24a0f5e228b67c90739697n/aMirai
2026-06-12n/aelf 391f08b27458f868bcf38007fa015a229daf3f32de37ea021479956742ae8189n/aMirai
2026-06-12n/aelf 785b6f9cacf2d8d57b22d7fed7db6fed92224fafbfa2b45f05e487eae9c68fdbn/aMIrai
2026-06-11n/aelf e24b3cfedd4712c1f75391f96576a772ca262e66e05ff8f1b9ad8ccf63b459a9n/aMirai
2026-06-11n/aelf 5652cc1834356a81a8f1c24f2cdd723e5bb983dd2e684832e2bf35dbee72b492n/aMirai
2026-06-10n/aelf 1d78b9ae870ed0c179ccd3548dec77f99430fe5d75f8d0362dcdbb0cf0516ce4n/aMirai
2026-06-06n/aelf cc69486256de47dde43a8c5645edd2b9e102b7c3c62e0d1930ca3852bffd882fn/aMirai