URLhaus Database

You are currently viewing the URLhaus database entry for http://genddos.st/bachekuni/ohshit.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3875535
URL: http://genddos.st/bachekuni/ohshit.arm5
URL Status:flame Online (spreading malware for 1 month, 24 days, 19 hours, 33 minutes)
Host: genddos.st
Date added:2026-06-24 12:32:33 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-08-18 03:00:24 UTC to abuse{at}stormindustries[dot]llc)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-18n/aelf b8b002ca4cd94868e1500ba1730fcb4be4d270672545c28c340decf0e088af89n/aMirai
2026-07-30n/aelf 452f40131b10db314303d499da82c8174b4296fa902d9dad5f0744bac0fbc1c4n/aMirai
2026-07-20n/aelf 850847440cf308046af0139b1c74e7059d19e82f591705f772d4568d854c1079n/aMirai
2026-07-19n/aelf 40538319f2440197c5e202605992cd1d2638e9d4cc747e8a16e429466262dea2n/aMirai
2026-07-05n/aelf 3f46f24356ee0ca1a8147a0deea5a584870bb1d99f3fcc996ced516830148778n/aMirai
2026-06-24n/aelf 6d87ae2ed432257f12b073709ea0668ec25548cb31281f53ff891a7eb3ac5f3en/aMirai