URLhaus Database

You are currently viewing the URLhaus database entry for http://154.6.197.37/bins/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3728703
URL: http://154.6.197.37/bins/arm6
URL Status:flame Online (spreading malware for 2 days, 15 hours, 8 minutes)
Host: 154.6.197.37
Date added:2025-12-07 12:56:09 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-12-07 12:57:16 UTC to abuse{at}cogentco[dot]com,abuse{at}logicweb[dot]com)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-07n/aelf fa681cc1deee3d95e892e274a4337a7531f1806b4079eb4bbab6679e3228390fVirustotal results 58.46%Mirai
2025-12-07n/aelf 5f96aa0a534f4dce0a9153f5dd4590fcd217e116d35f1cf5588ffd6525dd7f93Virustotal results 55.38%Mirai