URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/arm6.uhavenobotsxd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3686385
URL: http://94.154.35.154/arm6.uhavenobotsxd
URL Status:flame Online (spreading malware for 26 days, 19 hours, 32 minutes)
Host: 94.154.35.154
Date added:2025-10-24 23:37:09 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-24 23:38:14 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-20n/aelf 1350b69358cc22c12111c5f2f37c0ed39434c0345de97116aada4bf84d5ebc49Virustotal results 26.56%Mirai
2025-11-19n/aelf 37be4efb495085ef6955b10ae5576970708b82217486c1cb2517f7ec63e3d7f2n/aMirai
2025-11-19n/aelf 6e2be21fb84031d766130e63df54ac801afdcc52963e8f7ffe72681f572a6247n/aMirai
2025-11-19n/aelf abaa849cbe1e44ae1ea1d8ff67a6a2bdbf2db8abcbd5a91a5b23ca0a9b391ae2n/aMirai
2025-11-19n/aelf 0d5d5125176d5f3f86a5b2a8b9beba20cbc3489d74a0f4570a2bb3a635d371e4n/aMirai
2025-11-19n/aelf b1b0520a8149a658b9fd44296c620792bcc9cf0b66c8a4654dd75abc6fa05791n/aMirai
2025-11-17n/aelf 9b5a8390a4607c316a5fce9d77c1416ddcc5a864b9281d5abb82f516c955ab1eVirustotal results 25.00%Mirai
2025-11-10n/aelf 71e35346e597b57e5eb634bccc0e7b236d6befd16eb473c1ae89646696e7c0d0n/aMirai
2025-11-09n/aelf f3750e822022f8208978f978dfa9d6de8618cfab609e8178306e1e5920c6cfd6n/aMirai
2025-11-09n/aelf 415fc47700f65c8e14099c3fe1801e71cb1b088328d742cb3140dc3fe6fa3958n/aMirai
2025-11-09n/aelf e4c104d5118d215f01a97767753d97f7ce5e5a87b879fd8cc6f4d848bf578fb6Virustotal results 26.56%Mirai
2025-11-08n/aelf 1b8706c230fd34fead734150d64735fceb2190624af017e16fe3be354b6e7560n/aMirai
2025-11-07n/aelf 46b4c6c170f1adb4b5e31632a51afe697a2897378396fd16d8e0c99a0ec1fd13Virustotal results 25.00%Mirai
2025-11-06n/aelf 18a19da59770c9e9d64771118253d7751b9d3383c9fe488867f93d55a5cda6ffn/aMirai
2025-11-06n/aelf 50fa7ddf4b22fa23237c78b08866fb11769f79507b8230a7033af273f0cc9a43n/aMirai
2025-10-26n/aelf e92aed6d7e526d70dc68736244b15ff4fd856503fc02c4cdf9ae61facd846f8aVirustotal results 25.00%Mirai
2025-10-26n/aelf eaf09e686a80a943ee34abadef65f06cb165ad107160ef626aa079682e276612Virustotal results 26.98%Mirai
2025-10-26n/aelf f23af96e9f6782188937419070b4dc24c84a22fe42541a76ffe941d0869cc8bbVirustotal results 25.40%Mirai
2025-10-25n/aelf dd9c22b85ea68544b9d159dda8d59e6240161c1bfe50f01e3fb5d512a7a8be3bn/aMirai
2025-10-24n/aelf 697da91e58944fb9faaa97faa05c5a36f496c546166c341f92aeeb7a9a6e30a2n/aMirai