🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://92.5.66.49:8080/bot.arm64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3898737
URL: http://92.5.66.49:8080/bot.arm64
URL Status:Offline
Host: 92.5.66.49
Date added:2026-08-08 06:41:15 UTC
Last online:2026-08-14 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: OktayAlver
Abuse complaint sent (?): Yes (2026-08-08 06:42:14 UTC to abuse{at}oracleemaildelivery[dot]com)
Takedown time:5 days, 19 hours, 4 minutes Bad (down since 2026-08-14 01:46:46 UTC)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-11n/aelf b38e430116c0c1a0763055bcdc6e2aa84b96523c9854ca62b46394e8666c7927n/a
2026-08-09n/aelf c5e842833e6faf1b75ae02ccd9dd63b2a29747a3ff72673b7536b8af3da26f17n/a
2026-08-09n/aelf 19fb3181c49e4573382302bce2e612189105259ac86ec976227b09d0a6919875n/a
2026-08-08n/aelf 5cda20b9c5d242d96e39e8f3ed30e60256fc8ea3789ec8e37bd79af77e602346n/a