URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.43.158/disconnectraw.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3897609
URL: http://94.154.43.158/disconnectraw.mips
URL Status:Offline
Host: 94.154.43.158
Date added:2026-08-06 05:58:32 UTC
Last online:2026-08-08 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-08-06 05:59:18 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Takedown time:1 day, 19 hours, 5 minutes Poor (down since 2026-08-08 01:05:08 UTC)
Tags:DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-07disconnectraw.mipself d33f3b1668cd682ae4b7a049d2ec3ce5ca5f0de464061881948a6802ad8899f7n/aMirai
2026-08-07disconnectraw.mipself 59361ef6ce36865765e3f07506b99dd55373a8b31e2011b0f77c0d0ad9439126n/aMirai
2026-08-06disconnectraw.mipself 6058c04395b017bcb68befecb58f2b8bbd60f57a53a2650285108a2c847b69e8n/aMirai
2026-08-06disconnectraw.mipself b741e81dbe57b9162772caf66ef524eb5fd2c8d63ac4e8d179697fb28ee20113n/aMirai
2026-08-06disconnectraw.mipself b67d082f6b969b0b4f5c5e0658b106478fd05607d2927ec7cece8abed5c85848n/aMirai
2026-08-06disconnectraw.mipself 66e9aa24eb9f00590ceddf13af2837e47b0ba43a63db2091081c30c8ef4c3651n/aMirai