URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.43.158/disconnectraw.arm4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3897608
URL: http://94.154.43.158/disconnectraw.arm4
URL Status:flame Online (spreading malware for 15 hours, 2 minutes)
Host: 94.154.43.158
Date added:2026-08-06 05:58:32 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-08-06 05:59:18 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-06n/aelf dde5411d955c44f681783d58c927cd7367aa36635906573f25ba67fa59bf61c5n/aMirai
2026-08-06n/aelf d68dfaaf3fafdcf4eb14ac5fc595f28d1437da28d7a684ca57af114d3b0b6482n/aMirai
2026-08-06n/aelf 15e7ed72b583b5963afd09be21fa1c43c1634de711e97af81d30deb6ce7097ebn/aMirai
2026-08-06n/aelf a40094d0a0fcc6fad49a4fbf585327946a9870f4b285b6e1067e2aef5c9d8dfcn/aMirai