URLhaus Database

You are currently viewing the URLhaus database entry for http://37.44.238.94/nsharm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3353757
URL: http://37.44.238.94/nsharm5
URL Status:Offline
Host: 37.44.238.94
Date added:2024-12-17 11:50:07 UTC
Last online:2025-01-09 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 11:51:11 UTC to abuse{at}fiberway[dot]fr)
Takedown time:22 days, 18 hours, 57 minutes Bad (down since 2025-01-09 06:48:27 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-05n/aelf 45a5658d9de647b5f062c9b8839e66ced483772488a19f1375197e2b7bae17ffVirustotal results 24.19%Mirai
2024-12-28n/aelf 16391747c48945e0fde56308fe40f0ef4f0926dbf94862808d91574fdd1892e3Virustotal results 50.00%Mirai
2024-12-21n/aelf 54224f5b5cc2ce6f17833cf449420e27028233380e6d29d23c7ce06692258aa9n/aMirai
2024-12-20n/aelf 61ee479993ea6342e20591591ab68285e33093ea9f6b2a18899c176b6aa4e800Virustotal results 31.75%Mirai
2024-12-17n/aelf 34a9f4f587030b5834bf3194024722c22127e2d98c1f7542587abcffeebe7c7eVirustotal results 59.68%Mirai