🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://wemqmewkqewq.work.gd/armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3923505
URL: http://wemqmewkqewq.work.gd/armv6l
URL Status:flame Online (spreading malware for 4 days, 9 hours, 30 minutes)
Host: wemqmewkqewq.work.gd
Date added:2026-09-27 06:34:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-09-27 06:35:26 UTC to abuse{at}swissnetwork[dot]co)
Tags:botnetdomain elf mirai link ua-wget wemqmewkqewq-work-gd

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-30n/aelf 3649c5977d4116a8573220c2f7077abf53b951583d6f66154b48c2ce6f97c8a3n/aMirai
2026-09-30n/aelf 31052cb3bf27c7cacd2008e4bb875929bebae7da347b18ac1737bff3cb41eff3n/aMirai
2026-09-29n/aelf 7fad468e4d9bb06e388a731f87993331d6efc17701075a503cafd8270eae8404n/aMirai
2026-09-29n/aelf 68b13fa7f50b882a7ff30b9a79eb609404a1d5efb621ccea952f8fe94992a25en/aMirai
2026-09-28n/aelf 256b0dade89c39840f64dfd59ee13f0cb9cee3e604cfe32bc4193b888ca02d4cn/aMirai
2026-09-27n/aelf 4fcdb14419698bf94ccf820465504fa54da1372c69094601195112cc5a9fdb9dn/aMirai