URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.236/nz/nz.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3887329
URL: http://41.216.189.236/nz/nz.arc
URL Status:Offline
Host: 41.216.189.236
Date added:2026-07-16 20:38:32 UTC
Last online:2026-08-05 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-07-16 20:39:23 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:19 days, 4 hours, 53 minutes Bad (down since 2026-08-05 01:32:50 UTC)
Tags:arc elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-04nz.arcelf dab140cdf09dfaebe33704e08e6f230b8e2bb18859cfa7530551c023bb854a62n/aMirai
2026-07-25nz.arcelf 655e66d1fc8aa77dae0bef3ffd4016566a6c3e4e7ed44d163d7adc84361fe326n/aMirai
2026-07-24nz.arcelf 7b9c914e01014cdbc5d59cf24c628a19048e27ea77b9e83719f5a40f098c3ec2n/aMirai
2026-07-22nz.arcelf ff0505f010971ddaa354ff717283644d446b6ae27bd9f8ce2ff4a7ea575d3d18n/aMirai
2026-07-21nz.arcelf b833394b614d4635a17a3ae30d43380fbc0b8dcd7a8de601715f8d87e9489c85n/aMirai
2026-07-18nz.arcelf 9004c2c67764bfbe7db1b7750d18522aaaa005030698bc4302cfa188ff3f5465n/aMirai
2026-07-18nz.arcelf e7ffadca7485550fa00a049f12f3e7e957f7fc19dae3229927af7cc39b13ba46n/aMirai
2026-07-17nz.arcelf 09591253a95411d60c2b0d5384924aa7cafbceec1467c951c6bbb1655d748f0bn/aMirai
2026-07-16nz.arcelf 986e9d0bc12a96608d20689051056d8df7b5d510409ca84f2c73b234af3e4906n/aMirai