URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/x86_64.uhavenobotsxd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3714269
URL: http://94.154.35.154/x86_64.uhavenobotsxd
URL Status:flame Online (spreading malware for 1 day, 10 hours, 53 minutes)
Host: 94.154.35.154
Date added:2025-11-22 20:55:07 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-22 20:56:12 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:elf geofenced mirai link ua-wget USA x86

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-23n/aelf 4591c54052c787376ea64aae9e4297bedf835551d9e1c7db3c2e5e3f90bff02an/aMirai
2025-11-23n/aelf 85bc6f74b611809d8f5c930877e3b7198e886764235fb0c3266085400d01f8b4n/aMirai
2025-11-23n/aelf 4900de10166d8cc5412846c94b4b27469d1a63c95ac4656b9f064ed8e16ead98n/aMirai
2025-11-22n/aelf bc8e5cffd7dd12080436c205564f09b950c32b2aeb61630d696cc18f4d651941Virustotal results 20.00%Mirai