URLhaus Database

You are currently viewing the URLhaus database entry for http://6yd.ru/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3718740
URL: http://6yd.ru/arm7
URL Status:flame Online (spreading malware for 26 days, 21 hours, 50 minutes)
Host: 6yd.ru
Date added:2025-11-28 17:57:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-20 07:11:17 UTC to noc{at}pfcloud[dot]io)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-20n/aelf da83bdfce452041df71007b1463e562cc3403c9d01ed9fd97e6bc96ea47d2e36n/aMirai
2025-12-20n/aelf 1297fcf3c622cc0a02be1f24b86f750e9b1d221a61cfca443648fc9939a8720en/aMirai
2025-12-19n/aelf c819cd3e58864a49bd657b76cf4d8959b82e39ce99acd9e2cfd4658172aa5d64n/aMirai
2025-12-18n/aelf 0d2d03b4e4c382a9b5b6b8432bc99f0b6aef087dec7d5fa0c4578ddebba4176cn/aMirai
2025-12-12n/aelf 993920f995d1d60d9bf063876b2ffb03ba3106110070a64f8d66575c39154fedn/aMirai
2025-12-04n/aelf 547d1e75421bbbfe0492e2191417ad070d3e1e40db837e9aa4737c7946cd67b7Virustotal results 48.44%Mirai
2025-12-01n/aelf 3a669e4cd47445902a7efe698bb215d55bfaefc1c570e9044865e3470b312fc7Virustotal results 31.25%Mirai
2025-11-28n/aelf 21c9e1189e8447ddb5e233401d47ac4be0321d988e081a75a074d4414cf1a5a8Virustotal results 34.38%Mirai