URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.43.158/disconnectraw.mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3897619
URL: http://94.154.43.158/disconnectraw.mipsel
URL Status:flame Online (spreading malware for 1 day, 11 hours, 17 minutes)
Host: 94.154.43.158
Date added:2026-08-06 05:59:28 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-08-06 06:00:26 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Tags:DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-07n/aelf f2b379c510e605d6c2024bd5715fd20d5e85efd3a5201fb4c849d1d141ab5c3fn/aMirai
2026-08-07n/aelf a9a08daf07f1b3b65aefe346cece1f53a82d2dd69cd7f73a3827ae6f20c0d1bcn/aMirai
2026-08-06n/aelf fa12e417bf8d52cfac80d55adea71909109860b0a8f7fbd1e2486a39af6e1c13n/aMirai
2026-08-06n/aelf c99ece21a55494fdf66fd2a1ae90a4f1d90f218fccc6a0ec94d8a2098244091bn/aMirai
2026-08-06n/aelf 6c5c765cee5aecf2695cd1431129cb97cb79cc8372a3c536a7f3085a8a6f355cn/aMirai
2026-08-06n/aelf a7e7171bf00c928ad8db6e2485731cb3b5c9dfe6a8f1be318d3e495d9b7bdf07n/aMirai