URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/arm.uhavenobotsxd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3686382
URL: http://94.154.35.154/arm.uhavenobotsxd
URL Status:flame Online (spreading malware for 2 months, 1 days, 7 hours, 5 minutes)
Host: 94.154.35.154
Date added:2025-10-24 23:37:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-24 23:38:14 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 1300be15611ba32b7f330cb31de833f46c5ca2f43ae9133c064ca32e49cfd8d5n/aMirai
2025-12-24n/aelf 2dd132d1983268c8dc1a588af27a94355b8f50d1e37894893c0529dc915b04a6n/aMirai
2025-12-22n/aelf 9e2ebe9f81e7b1fe0b3e25cdb4b43ab7bf8af4126e52ec9ccbb0333e24215ff7n/aMirai
2025-12-22n/aelf f11cfa41192f935db9d5a29b1026a54ab5827a2386ca390c23ddc650ba370651n/aMirai
2025-11-29n/aelf 5555c88764897e7db620f209f7a54eb5bc1fdd0b6a28f3630e61adb72bcf930fn/aMirai
2025-11-28n/aelf fa54862eddc29aeb63d5747d100da6340bb059e07012fa2aac13063c6ada94ffVirustotal results 29.69%Mirai
2025-11-25n/aelf 18d0cc7b40a193a55589f14b91d4f3243f32dc354f5265422eae9637f84fa891n/aMirai
2025-11-24n/aelf edb1379d31f273bdc49f66111b5418dce65340c5cffda5d1a25b3f61c796e9deVirustotal results 38.71%Mirai
2025-11-23n/aelf 7df1c3149696c1edadebca4f72173f7c6feadbdb325c5c7d163d2801ccef3ec8n/aMirai
2025-11-23n/aelf 41632af09f181889fae7cc2a7068567db4dde177382780b71e81d69907c763f7n/aMirai
2025-11-22n/aelf 7cdf54031e1486466482989145c606397dd968669ca32a49c9c301a75b831b63n/aMirai
2025-11-21n/aelf c2ffe399cde2e546f3b54b616a9e59b664a2742612a519199f6246b1ee4a53cdn/aMirai
2025-11-20n/aelf 1fb350e213500aa096d34afa25b2f4a4040a8cd497487546860873ceeb1f583bn/aMirai
2025-11-19n/aelf feb25d9fb8ba8d13338871d7ffcd04082c2ff65b7c9017f86760e2347f82c08an/aMirai
2025-11-19n/aelf 05130dd4cf03503c7d14ead08003b6477cf49c22645b54de637ade2b9a27f75cn/aMirai
2025-11-19n/aelf 2692a4ecd625b6f2b96a1cda0252acd69b0100b567f94369a1eec32c0a910394n/aMirai
2025-11-19n/aelf 30630201081f50079c8ee45c86e118071e787a402d72dcec019f09364d9482ecn/aMirai
2025-11-17n/aelf f09ffd5059c0a7ccfdbf69b0e3c370e5f0ccfe5b4a3b5492ed60ca9ce83fc979Virustotal results 23.81%Mirai
2025-11-10n/aelf 23976ea79423f602b270e2bede8cd5db6c4c4bb7c9b410c1e5db946ad57d3c2fn/aMirai
2025-11-09n/aelf 1830697ccda591cba76a27f1d292b62aca1f2d9b02de8b0dab34cbcfb80afee9n/aMirai
2025-11-09n/aelf 16011b3f5882eab56182ac7259954077977cf0872a3654d0ad2f4b428a8cec53n/aMirai
2025-11-09n/aelf a0e8dee32ca93ba9721fea42e5e20c88b5f316d34c971961afe9e8ecf99165fdVirustotal results 26.56%Mirai
2025-11-08n/aelf 80f347a65e6868bbe1faebbef90951118c936eb58270bbfcac778a32f20c3d52n/aMirai
2025-11-08n/aelf 515d159bee465a48f25f3fac2248d08303a999479fcfba8ea2ef63287244402en/aMirai
2025-11-08n/aelf 2c600d1b808cb5272cebb0de29bcbe8f453a51a05d036c693e0f378f57b41685Virustotal results 27.59%Mirai
2025-11-07n/aelf 9faf9b7146b3b69896e53386006d1d16d5b551e57ca57310eebd8c2459050412Virustotal results 28.12%Mirai
2025-11-06n/aelf 77a283a2851ddd6334ee9465e2d1ec57fd1edc02497a10f14480ecbdef9da584n/aMirai
2025-11-06n/aelf c79fff4249ecdac46dac9854016e80e38c720b4368c0bfe10d6e349be8b68ccdn/aMirai
2025-10-27n/aelf 8762dee4bddacfed096e23ad0a7c9ef6b2697c9a89b128d21418c99c5924b93eVirustotal results 27.42%Mirai
2025-10-26n/aelf 313f7d86508ca0b02ea41d17a66ce728b3e5f04dc803aeedd078ba4667f71d8fVirustotal results 25.81%Mirai
2025-10-25n/aelf ed63c838a4050bc1d4527c96cf2b6f042bea2b2b68d777f339d06cd9fe2d6ab7n/aMirai
2025-10-24n/aelf 8f9ffa264b38c3144ed371b48a44cd334ff6474af8ff0793b3e685f9dcc38a5bn/aMirai