URLhaus Database

You are currently viewing the URLhaus database entry for http://94.183.232.177/ohmygawdignoreme/wewe2.johnsmith which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3703987
URL: http://94.183.232.177/ohmygawdignoreme/wewe2.johnsmith
URL Status:flame Online (spreading malware for 6 days, 3 hours, 0 minutes)
Host: 94.183.232.177
Date added:2025-11-13 00:25:11 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 00:26:14 UTC to abuse{at}cloudbackbone[dot]net)
Tags:elf geofenced mips mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-17n/aelf fd43cd285c221153bd79cc46a623a0e7084711f50a3854429e7459b3bba8cc99n/aMirai
2025-11-16n/aelf c3a7e303e13cd1247a702a88b546ab8bbba8b732e4e8eeab9d4e884ff8152562n/aMirai
2025-11-14n/aelf 73915b326891a0d4fc56c7eaf0627310161e7ca6a5720c6ddc5a9f88d791f748n/aMirai
2025-11-13n/aelf 8bfdfa1eda7dadba0dae04364ba346892997a495f318785f6c91429ba878d826n/aMirai