URLhaus Database

You are currently viewing the URLhaus database entry for http://37.44.238.94/nsharm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3353759
URL: http://37.44.238.94/nsharm
URL Status:Offline
Host: 37.44.238.94
Date added:2024-12-17 11:50:07 UTC
Last online:2025-01-09 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 11:51:11 UTC to abuse{at}fiberway[dot]fr)
Takedown time:22 days, 22 hours, 23 minutes Bad (down since 2025-01-09 10:14:40 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-05n/aelf 2f764a8c1c9131f763a1951f7ac5d3c95731dc13ee8d7b14823a53a9f34662d3n/aMirai
2024-12-28n/aelf daada5e94b6f69ad4e05132e8f214e389903db52e41b3d429ec2f7b1e5e9a240Virustotal results 47.62%Mirai
2024-12-21n/aelf 218e5746aba8cec848c85401115db0ed0b30245084935813efc756434389c4c0n/aMirai
2024-12-20n/aelf 536e51ec95627d4b8dc490b09f9040ea631ec39036c54c38011cd54cd30728f2n/aMirai
2024-12-17n/aelf 1752a1eff046cdaa72b269218512ff202712e43b3b253362d5ef945134b44cfeVirustotal results 58.73%Mirai