URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.43.158/aarch64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3896595
URL: http://94.154.43.158/aarch64
URL Status:flame Online (spreading malware for 2 days, 3 hours, 34 minutes)
Host: 94.154.43.158
Date added:2026-08-04 05:45:29 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-08-04 05:46:21 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-06n/aelf 0663605009e6a08c531bd44d9d8b0f5272526562d7401e4c209ab69e1af18497n/aMirai
2026-08-06n/aelf fd572d74d7905f517fef099b3304f09f87029c94fb6080827f985635be919d67n/aMirai
2026-08-06n/aelf 049768ce81f1310f8bab20dc015e9dc515c390e53ad3479858292c4f68fdc3f6n/aMirai
2026-08-05n/aelf 1d73e05dc57be92556585d06299e706a7dbf66203d5770f8dfdd433481b87ac9n/aMirai
2026-08-04n/aelf 480319a161dcbd7aba883f7950b690819552f4d19b50c500a6310f93424edfe7n/aMirai
2026-08-04n/aelf b3e14fae58ed2e9652bb858f3387c4212042a9e71225c27181a1a1447641b928n/aMirai
2026-08-04n/aelf 311a51ead623e45f2e5310236cc0db150ad92dbafbdffc09593283b2172529a0n/aMirai