URLhaus Database

You are currently viewing the URLhaus database entry for http://6yd.ru/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3718740
URL: http://6yd.ru/arm7
URL Status:flame Online (spreading malware for 1 month, 17 days, 23 hours, 19 minutes)
Host: 6yd.ru
Date added:2025-11-28 17:57:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-01-03 20:38:12 UTC to report{at}abuseradar[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-15n/aelf 5e611c0ad2bb70becdf4a772162a14356ee476e3e0bebabd21cd00860bf4e4ccn/aMirai
2026-01-14n/aelf e4cbc94d05cf68b17152711ab035bfb71e9d98e36b342ce45198d26f1d374e6an/aMirai
2026-01-04n/aelf 30c1fa4827381cc432b67aa1c1608170be61258bddd3a7fba2c66443e7ed88f3n/aMirai
2025-12-31n/aelf b4c333b0e99995c57a7272c9676a3d490f36cdd60a7ad16f71a78dbfa53418f9n/aMirai
2025-12-30n/aelf c329cbdcfb92555ba6a5693ddf7c9a39c641c8b8434638284c9e87915e9f87b9n/aMirai
2025-12-26n/aelf 2da222e7113d9131f60467f8ed3a917c9939fd65683709a459589fbf8978849fn/aMirai
2025-12-20n/aelf da83bdfce452041df71007b1463e562cc3403c9d01ed9fd97e6bc96ea47d2e36n/aMirai
2025-12-20n/aelf 1297fcf3c622cc0a02be1f24b86f750e9b1d221a61cfca443648fc9939a8720en/aMirai
2025-12-19n/aelf c819cd3e58864a49bd657b76cf4d8959b82e39ce99acd9e2cfd4658172aa5d64n/aMirai
2025-12-18n/aelf 0d2d03b4e4c382a9b5b6b8432bc99f0b6aef087dec7d5fa0c4578ddebba4176cn/aMirai
2025-12-12n/aelf 993920f995d1d60d9bf063876b2ffb03ba3106110070a64f8d66575c39154fedn/aMirai
2025-12-04n/aelf 547d1e75421bbbfe0492e2191417ad070d3e1e40db837e9aa4737c7946cd67b7Virustotal results 48.44%Mirai
2025-12-01n/aelf 3a669e4cd47445902a7efe698bb215d55bfaefc1c570e9044865e3470b312fc7Virustotal results 31.25%Mirai
2025-11-28n/aelf 21c9e1189e8447ddb5e233401d47ac4be0321d988e081a75a074d4414cf1a5a8Virustotal results 34.38%Mirai