URLhaus Database

You are currently viewing the URLhaus database entry for http://14.225.206.204/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2730519
URL: http://14.225.206.204/sh4
URL Status:Offline
Host: 14.225.206.204
Date added:2023-11-13 21:07:08 UTC
Last online:2023-12-03 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2023-11-13 21:08:05 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:19 days, 12 hours, 56 minutes Bad (down since 2023-12-03 10:04:22 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-27n/aelf b07d67dc564615e50d9cb23d700157610076458a6b909414244b2459fb9431c8n/a 
2023-11-25n/aelf 657adf416a1a6b6adc93f4a8164f17302bea1df279e696c16f28197d6cc4aa03n/a 
2023-11-21n/aelf 1f70496d5fedfb28b6508ec1a528c30a3566c40ddbeba5176c1fc3f43b076ec1n/a 
2023-11-20n/aelf 0af3460efab2be405ad196537f5bf80e2f5a7854ec8441885b129cffe01ca3fcVirustotal results 67.74%Mirai
2023-11-16n/aelf fadbdac319e342e1d9f3c558d266f8290e9b1563921a1821f005889f87e2855en/a 
2023-11-13n/aelf 363b21a807e343df49e37ec59d49612c3059a0a9439440a6a4088a7444876d93n/aMirai