URLhaus Database

You are currently viewing the URLhaus database entry for http://31.56.209.153/nz/nz.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3892232
URL: http://31.56.209.153/nz/nz.arm7
URL Status:flame Online (spreading malware for 24 days, 14 hours, 51 minutes)
Host: 31.56.209.153
Date added:2026-07-26 17:49:21 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-07-26 17:50:19 UTC to abuse{at}swissnetwork[dot]io)
Tags:arm elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-04n/aelf 131c71f16cb132c6258ddae86b6e21aca7c07b3cf50b1d2efb66ecb55af78feen/aMirai
2026-08-03n/aelf 1722375fa81d3e17092350c51ee6d7068c556c1d137c6d47aa027a18f84f4817n/aMirai
2026-08-01n/aelf b419f6e0ab5e13bbab3bbba935a46020e40da4acfa3112fd3c0e9b2cbe268686n/aMirai
2026-07-31n/aelf ecd6239cfb44faf5588d7d520f25d8f52c3f8e531bd3aa02af757a5463beee5cn/aMirai
2026-07-31n/aelf 2c748313a5a75f19574f44dd6db9c1c064ddc494132a91a46ff71be7b6f60d61n/aMirai
2026-07-26n/aelf 5a395c826117e12109b896d177ec44700cabb07a1ce61414c8358df7bbfc2b91n/aMirai