URLhaus Database

You are currently viewing the URLhaus database entry for http://selfrep.carteldesinaloa.ru/389242390482/nuklear.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3277468
URL: http://selfrep.carteldesinaloa.ru/389242390482/nuklear.sh4
URL Status:Offline
Host: selfrep.carteldesinaloa.ru
Date added:2024-11-05 19:16:07 UTC
Last online:2024-11-14 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-11-05 19:17:08 UTC to abuse{at}virtualine[dot]org)
Takedown time:8 days, 14 hours, 32 minutes Bad (down since 2024-11-14 09:49:16 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-07n/aelf ef60f292d4420a647e22646d463d53daf6c6679ea5f2a035b8e2141dfde4aa52Virustotal results 60.94%Mirai
2024-11-06n/aelf 236137b3e9c4b109379a4a6d902b79d6797c24f0edbc2ceec9ba0f512dec90cbVirustotal results 60.94%Mirai
2024-11-06n/aelf 2ce1b4eb3dc40380785bbf345167e1584ae9b7962e16dfd766830069ead2ec59n/aMirai
2024-11-06n/aelf 07eb1f88c49e30f7129930886b9299a88e60daad15567ff19c3bc159db01fb6bVirustotal results 61.90%Mirai
2024-11-05n/aelf f41535767336f7e8a8129fad104af0a662b0a4dea4a7cdf440c70c7eee254e38Virustotal results 64.06%Mirai