dl.armour-inc-down.net
Checking live DNS resolution...
100/100
CRITICAL RISK
63
Malware URLs
2
Resolved IPs
0
Abuse Reports
24
Active URLs

Threat Intelligence Summary: dl.armour-inc-down.net

Risk Level: CRITICALThreat Score: 100/100

Assessment: dl.armour-inc-down.net is actively hosting 24 malware URLs across 2 resolved IP addresses. The number of active endpoints suggests ongoing, organized malware distribution. This domain should be blocked at the DNS or firewall level. Malware families associated with this domain include zip, pw-DR67KVLD, pw-4DKCUJ4DDXS.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 63 — Active: 24 — Resolved IPs: 2 — Abuse Reports: 0

First Seen: 2026-03-13T23:21:29 — Last Online: 2026-04-25T00:08:54

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

dl.armour-inc-down.net has been associated with 63 malware URLs , of which 24 are currently active . The primary threat types are malware_download, malware.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2026-03-13T23:21:29
Last Seen Online
2026-04-25T00:08:54
Data Last Updated
2026-05-15T05:01:04.654270
Status Activity Timeline (50 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

ONLINE
https://dl.armour-inc-down.net/in/?HashCracker
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?SpotifyViewBot
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?GTAVCrackInstaller
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?FortniteAimbot
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?YouTubeViewBot
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?AdobePSPremium
First detected as online
ONLINE
https://dl.armour-inc-down.net/in/?adobecrack
First detected as online
ONLINE OFFLINE
https://dl.armour-inc-down.net/in/?AdGuardPremiump6
Status changed from online to offline
ONLINE
http://dl.armour-inc-down.net/in/?KIDDIONSMODMENU
First detected as online
ONLINE
http://dl.armour-inc-down.net/in/?AdGuardPremiump0
First detected as online
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU3
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU1
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU2
First detected as offline
ONLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU
First detected as online
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU5
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU8
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU9
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU6
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU7
First detected as offline
OFFLINE
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU4
First detected as offline
Showing 20 most recent changes of 50 total
Associated IP Addresses (2)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

172.67.181.61
0 abuse reports
104.21.18.80
0 abuse reports
Malware Classification
zip
Malware family "zip" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
pw-DR67KVLD
Malware family "pw-DR67KVLD" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
pw-4DKCUJ4DDXS
Malware family "pw-4DKCUJ4DDXS" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Vidar
Forked from Arkei stealer in 2018, sold on Russian forums. Downloads legitimate DLLs at runtime to avoid detection. Targets browser data, crypto wallets, 2FA codes, and Discord tokens. Often distributed through cracked software and YouTube tutorial scams.
pw-NMCLDJX3SK2
Malware family "pw-NMCLDJX3SK2" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Malware URLs (63)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://dl.armour-inc-down.net/
Active Threat
Type: malware
https://dl.armour-inc-down.net/in/?SpotifyViewBot
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-24
pw-DR67KVLD Vidar
https://dl.armour-inc-down.net/in/?FortniteAimbot
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-24
pw-DR67KVLD Vidar
https://dl.armour-inc-down.net/in/?HashCracker
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-24
pw-DR67KVLD Vidar
https://dl.armour-inc-down.net/in/?GTAVCrackInstaller
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-24
pw-DR67KVLD Vidar
https://dl.armour-inc-down.net/in/?YouTubeViewBot
Active Threat
IP: 104.21.18.80
Type: malware_download
First Seen: 2026-04-22
pw-DR67KVLD zip
https://dl.armour-inc-down.net/in/?AdobePSPremium
Active Threat
IP: 104.21.18.80
Type: malware_download
First Seen: 2026-04-21
pw-DR67KVLD zip
https://dl.armour-inc-down.net/in/?adobecrack
Active Threat
IP: 104.21.18.80
Type: malware_download
First Seen: 2026-04-20
pw-4DKCUJ4DDXS zip
http://dl.armour-inc-down.net/in/?AdGuardPremiump0
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-16
pw-4DKCUJ4DDXS Vidar zip
http://dl.armour-inc-down.net/in/?KIDDIONSMODMENU
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-16
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU8
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU
Active Threat
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU2
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU1
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU6
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU5
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU4
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU3
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU7
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
https://dl.armour-inc-down.net/in/?KIDDIONSMODMENU9
Taken Down
IP: 172.67.181.61
Type: malware_download
First Seen: 2026-04-15
pw-4DKCUJ4DDXS Vidar zip
Showing 20 of 63 URLs