URLhaus Database

You are currently viewing the URLhaus database entry for http://www.savaswsd.duckdns.org/huhu/titanjr.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3592188
URL: http://www.savaswsd.duckdns.org/huhu/titanjr.arm7
URL Status:Offline
Host: www.savaswsd.duckdns.org
Date added:2025-07-29 04:25:46 UTC
Last online:2025-09-20 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-20 14:23:10 UTC to abuse{at}cheapy[dot]host)
Takedown time:1 month, 27 days, 2 hours, 36 minutes Bad (down since 2025-09-24 07:02:36 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-20n/aelf fdc864a8a3fac746362f853859ddc92efd7d9bf1234059e46e53e7f540b3d2c4Virustotal results 26.56%Mirai
2025-09-13n/aelf 6afcf571eec90f00a93b8bf4568f58729404a58aaa8fc61cb8a93f94951b8944Virustotal results 12.50%Mirai
2025-09-01n/aelf 936b1cd7246aa104ef7790e3844ec6124f4a39639e9d4baadebadd5829d8bd96Virustotal results 20.31%Mirai
2025-08-17n/aelf b3d0d346c9eef185909d0c39135a1a6e17e819d1f211d0d69433927a16a8aa8an/aMirai
2025-08-16n/aelf c1a0810b877bd031bc1d824645ea4ec067a5ba463f8023f81431ae4613a68a1eVirustotal results 20.31%Mirai
2025-07-29n/aelf 08588e5fbc83e9728e96ecc9944b6b98bb813d81e0348265374d4f56ce23d166Virustotal results 48.44%Mirai