URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/arm5.uhavenobotsxd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3686383
URL: http://94.154.35.154/arm5.uhavenobotsxd
URL Status:flame Online (spreading malware for 28 days, 6 hours, 18 minutes)
Host: 94.154.35.154
Date added:2025-10-24 23:37:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-24 23:38:14 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-22n/aelf 99ffa905d34dcfbbcc2042d08e9374446a610d0a8a027dee6f35cb9447a23f35n/aMirai
2025-11-21n/aelf 70e9ef0bc045b5e8372365a29711930cac12a6fff8ca7a2086d79c43d7233ec6n/aMirai
2025-11-20n/aelf c3477c76a49468aa394c9103c7f696729e38c93de3730cd490a7ad86deb23751n/aMirai
2025-11-19n/aelf 2ff396138f8ca91a99089e4fe36ed5ef28f1f9d5ee2a5cb7e76a87a5e8b0bb5eVirustotal results 26.56%Mirai
2025-11-19n/aelf c9cd7556758e1fea7c02750b51d18f14896df5032c80f879775e0af5136a5b5fn/aMirai
2025-11-19n/aelf b7a7aebfdcdb27823b44fcdd76de61a9055493606ab384ca7a83876f58beb8adn/aMirai
2025-11-19n/aelf 20b7ea37225768937eb73ff9799dae45b1f6faf616295d5e51bdc68898286a3cn/aMirai
2025-11-19n/aelf b77d1577f842c3d59eff15180fe700767d78209f63cadbc4a4a4e7e6b5b223b9n/aMirai
2025-11-17n/aelf 95583072befb98cb0ae7c0f79e7dc791bf6678e3e77aebf0bff11d42901ca7a8Virustotal results 26.67%Mirai
2025-11-10n/aelf fd585f5332b4643a4f43b7ac53b03cfc6115bf26af43678f66a10587581eeea7n/aMirai
2025-11-09n/aelf 36fbd489c18453a8751fa85aa1cd7f3e803c056a370f92b787ae9f8b0cfa4cf9n/aMirai
2025-11-09n/aelf 6677a0194c095e6e649c3289f979c23ed9f81b1ab72371d01dd99076b988dbd0Virustotal results 28.12%Mirai
2025-11-08n/aelf 7ef0716357c8556aedbc946a393250b22e2be7950cc2449a4427efa6f98f469fn/aMirai
2025-11-08n/aelf e6e5ed27944b9b91084a6781094af3c8fdb8f647150a502b94bf0b1d84c258d7n/aMirai
2025-11-08n/aelf 6bbeb68909bd958c5974ce6e230e8d592f126a6d292fb5dd477a8663d4d1da0eVirustotal results 31.25%Mirai
2025-11-07n/aelf f60f341b795b873128937cde0f633cb177f8b94f772a673f091a32f2b6315a0cVirustotal results 26.56%Mirai
2025-11-06n/aelf 53bea745eaa1eb5e3a4e087394bdd501ed55aabe3616a47d998125dc7a310eebn/aMirai
2025-10-26n/aelf fe806e894a9e8a7b5632cc2bebb52661f467b6f1642ee24ec973e017581c3e86Virustotal results 27.42%Mirai
2025-10-26n/aelf 50728b13bd626ab0bbe19a91a6a60c3ab9aea987169392b8a9cc2fafe4347869Virustotal results 26.56%Mirai
2025-10-25n/aelf 916deb28170fa36ffb388fee172832a21e6ecd00097cd4ef5bec8dfd9c5828b8n/aMirai
2025-10-24n/aelf 12bac178d6dfa5571db91abc4bc6480aaa4c1ea3d7b38a2cad831cdadee5b6f9n/aMirai