URLhaus Database

You are currently viewing the URLhaus database entry for http://bonet.networkbn.com/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2765486
URL: http://bonet.networkbn.com/sh4
URL Status:Offline
Host: bonet.networkbn.com
Date added:2024-02-20 13:06:11 UTC
Last online:2024-02-29 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-02-29 04:15:09 UTC to admin{at}serveroffer[dot]lt)
Takedown time:24 days, 0 hours, 53 minutes Bad (down since 2024-03-15 14:00:22 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-13n/aelf d4a59b3234d76c91c61a320166cadaf16833418e59ca1cd02b7c28111d7e7e18n/a 
2024-03-02n/aelf a4fc40efe4a920c5a9dc8fcfec9ce8a4fd1924370cad43f40ac7d2ca815a79b1Virustotal results 43.55% 
2024-03-01n/aelf 2439c060180d01b75ab71cd4540412b08a5a62e7bfff1802ae791ed637e33200n/a 
2024-02-27n/aelf 252998a82388e0df00072d4b99fcbd6bba9fa9011f62aabe63ccf24fae65a328n/a 
2024-02-27n/aelf e69f56d053795070f66987c2d965bcd108f6c27d380e036e941d994fc691e023n/a 
2024-02-21n/aelf cb37e173a47fdfa44db8227f3a913689f3b422dc298f44f6db8feea852878099n/a 
2024-02-20n/aelf f08fe4e136d777369f9963a7baaf60eac86551951758386e6e2aff3b8468af96Virustotal results 61.29%Mirai