URLhaus Database

You are currently viewing the URLhaus database entry for http://185.142.53.6/tsh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3174319
URL: http://185.142.53.6/tsh4
URL Status:Offline
Host: 185.142.53.6
Date added:2024-09-15 13:52:05 UTC
Last online:2025-02-28 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2024-09-15 14:38:08 UTC to abuse{at}fiberway[dot]fr)
Takedown time:5 months, 16 days, 0 hours, 49 minutes Bad (down since 2025-02-28 15:27:15 UTC)
Tags:elf gafgyt link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-20n/aelf 564c243b1f553f14bc3b7bb40299a554e40d02eaedd7c7f17da7259221685fb7Virustotal results 20.97%Gafgyt
2024-12-04n/aelf e6ff63d78c6c1f39f833f009c70b5a0163e7ac7b50b4d3183e4892a126544080n/aGafgyt
2024-09-24n/aelf 740c6ef38f919b7a6d0a6365a26e0bfea42f553536d8b516744a268454313474n/a 
2024-09-22n/aelf 035bb464c26c644208c7aeed4dbe5019327a6830062a6c0328a9115048e06439n/a 
2024-09-18n/aelf 65bf05de3c27342c9d3b51a7ddee039c763e099cf109f092e5105a1af81e6bffn/a 
2024-09-18n/aelf 2fe2483e41aadf20295bf3556788ceda7db4417cfb37c82dbf90a9b48e09db51n/a 
2024-09-15n/aelf 472d44354422077f97ca61c2137b6a1693f97b0639562b1f1ea4f8f42c883e86n/a 
2024-09-15n/aelf bb2588d68efce08c141e35ca0d4e8b0f9481b2407a78492e4a7d03d07a12f3dcn/a 
2024-09-15n/aelf de73a0d00f1ff0149848e289a39153ae468294d199217f6086368fb3b43d000eVirustotal results 14.06%