URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.154/weball.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3734248
URL: http://94.154.35.154/weball.sh
URL Status:Offline
Host: 94.154.35.154
Date added:2025-12-15 20:30:07 UTC
Last online:2025-12-24 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-12-15 20:31:14 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Takedown time:8 days, 22 hours, 6 minutes Bad (down since 2025-12-24 18:37:37 UTC)
Tags:geofenced mirai link sh ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24weball.shsh f76b64d42bb61296d51f9c312fda96f8bfffc55f9e8f8a10d3c79faa6e314219n/aMirai
2025-12-22weball.shsh 32243b67c0497c60f7cf939615958a00204bde921a2c856e9a7afb8ba930f807n/aMirai
2025-12-15weball.shsh f9b3234914685a761c8b371d7908a6c358ca0df187d777a38523ade77c9be18cn/aMirai