URLhaus Database

You are currently viewing the URLhaus database entry for http://allahvsataturk.duckdns.org/UnHAnaAW.spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3667549
URL: http://allahvsataturk.duckdns.org/UnHAnaAW.spc
URL Status:Offline
Host: allahvsataturk.duckdns.org
Date added:2025-10-10 18:18:23 UTC
Last online:2025-11-12 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-11 19:08:12 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 26 days, 4 hours, 24 minutes Bad (down since 2025-12-05 22:43:44 UTC)
Tags:botnetdomain elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-01UnHAnaAW.spcelf d2ea24af845b1bf794f1e3159f4420bad12c54b5da1b761c6571b01e83cc4d28Virustotal results 56.25%Mirai
2025-11-11UnHAnaAW.spcelf b19d8245d8adeb27944deefd2ae7662e4bda0c3098c964e94b5326acbec78755Virustotal results 56.25%Mirai
2025-10-10UnHAnaAW.spcelf 8122b636fe0eca6db90e4ae02ca55ee5b391c8cc1472f2445ec25833fddcdef4Virustotal results 56.25%Mirai