URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/arm7.uhavenobotsxd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3686384
URL: http://94.154.35.154/arm7.uhavenobotsxd
URL Status:flame Online (spreading malware for 26 days, 3 hours, 37 minutes)
Host: 94.154.35.154
Date added:2025-10-24 23:37:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-24 23:38:14 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-19n/aelf 6bdb2f60a123e87811a1f292ad2b1212a376ac8c9336bf5c0cbdb24d3119923dVirustotal results 28.12%Mirai
2025-11-19n/aelf 68fcc475742b0e14fd844f6bd18562bb5cc7b5d5a63617f8e74c4c3dd157a1fbn/aMirai
2025-11-19n/aelf a4885db138961a9480231b6405a7703e6908935a514f260d56a85778e145e6e0n/aMirai
2025-11-19n/aelf 8e506d03141a9379c6b0259e1328076f2e26805117d977f73c76bb8b1b060260n/aMirai
2025-11-17n/aelf 47fe13793e0ce3f90a57bd9147a192832d95d61f0799068b763bc874db1ccf77Virustotal results 26.56%Mirai
2025-11-11n/aelf ff551e04680991c96c2dad1e09b926ba6d495b85b4a0487a0c7bb59af1681077Virustotal results 29.03%Mirai
2025-11-10n/aelf 7824ecf222bcfd3f51efa8f1b69b4fb95df0a2390a2d19c2ed963da34e612c7an/aMirai
2025-11-09n/aelf 61ae0cbae9991c012f36e341e914df42b6bda20b9a48925a2f0092892f7e15a8Virustotal results 31.25%Mirai
2025-11-09n/aelf 54a1d616922d58c62a58c6eea2d05da215ff61a35b076dd91c1d79561cc08a5an/aMirai
2025-11-09n/aelf 2da34dc801362d3d580cd01bf24dd1680ef4f95f933396163782fd8b3c6dbf41n/aMirai
2025-11-08n/aelf 9a54f3c7cfaf359de17b534a553207fd32c511655a73277d6d24657887dae1d5Virustotal results 26.56%Mirai
2025-11-08n/aelf eef5bcc48b9e0a7db4cc164a652d73c25b9d793ca1c4ea37795ddd2f7be1c94aVirustotal results 31.25%Mirai
2025-11-08n/aelf 47d61977f0cc76324bb56ead1e8fae0aeff44c738ef3e78736a667398244bfb3n/aMirai
2025-11-07n/aelf c529bb8355e49b04a26d5b66f51b35e7c7e0a83fa76289009de95fe5253822f7Virustotal results 31.25%Mirai
2025-11-06n/aelf a4c17ea70f07a23ad28b3ec7ebf616155b070d19f5cec19598df55d3861d52abn/aMirai
2025-11-06n/aelf 683b7fcb91a3d1482b707933f25d7902e318401958e04880d24803bea2eaa524n/aMirai
2025-10-26n/aelf 2953d20485129d2597d9db9892c2c88f4b3b2de548430b2ff7a86ce16a317cc6Virustotal results 34.38%Mirai
2025-10-26n/aelf 0555e8b77cd196c440fb51bb6cb815da42def1764ec32f68b710fdac4ee3cf4dVirustotal results 26.56%Mirai
2025-10-25n/aelf c702f5d3053665ecef654995eefea5ae506227edf2723c40798a6cd4bcaba5ccn/aMirai
2025-10-24n/aelf 058a835ef8b70912b9eecb24768a798ec81433cd59d54f7873fe909a08e6cb6fn/aMirai