URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.22.13/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2045414
URL: http://23.94.22.13/sh4
URL Status:Offline
Host: 23.94.22.13
Date added:2022-02-16 15:33:05 UTC
Last online:2022-04-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2022-02-17 17:14:01 UTC to report{at}virmach[dot]com)
Takedown time:1 month, 28 days, 18 hours, 35 minutes Bad (down since 2022-04-17 11:49:43 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-09n/aelf 6c4bd7fc7c0cca5d4ccbd35e30013d51c57f1dfc7d823ab6295342989dee1b01n/a 
2022-04-02n/aelf 90be08e9070da6dc3c34162a8db38481c179d8c02c5f76ef433381af0eddb9a7n/a 
2022-02-21n/aelf bb4afbfa1103ef2e7a39c32ddde3a1ca6663c2e4e0c68f75f07f5e0e1918be2cn/a 
2022-02-16n/aelf 67d203aaa61f5277d3b60f7a65c61fe34d3be31e12db72c92512e7a4c8d359feVirustotal results 59.02%Mirai