URLhaus Database

You are currently viewing the URLhaus database entry for http://185.204.217.174/bins/yakuza.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1945590
URL: http://185.204.217.174/bins/yakuza.sh4
URL Status:Offline
Host: 185.204.217.174
Date added:2022-01-03 08:02:05 UTC
Last online:2022-01-08 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2022-01-07 13:21:37 UTC to abuse{at}cyberfolks[dot]pl)
Takedown time:7 days, 9 hours, 17 minutes Bad (down since 2022-01-10 17:22:05 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-10n/aelf 2a61734126904d5323cc0d228b1d840703e4ef66ad105691c6af3398a3b921cen/aMirai
2022-01-04n/aelf 9fbb171a2e1ac96ab8951c560dd9385f7aacff4f9aec3b17f77d2eda463513f8n/a 
2022-01-04n/aelf 5c315407730a6f837d5c0f1a86bf2387654f02018befafa9662028e1a40e7650n/a 
2022-01-04n/aelf 0d971f390c98f05f3d72b1706c03890eb35fff5d3832a7b17f835ae6797845a9n/a 
2022-01-03n/aelf 9bfca272054bc1459253b0f35a94312c4dde18617e9578fd0f49c6a5a322b048n/aMirai