URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.140.135/w.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3430679
URL: http://176.65.140.135/w.sh
URL Status:Offline
Host: 176.65.140.135
Date added:2025-02-07 06:41:05 UTC
Last online:2025-03-12 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-07 06:42:07 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:1 month, 3 days, 2 hours, 37 minutes Bad (down since 2025-03-12 09:19:29 UTC)
Tags:mirai link sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-06n/ash 9e612c35bbd317f30442ac93835852353a0d30a6429dfcb3bdf812f0f132196en/aMirai
2025-03-05n/ash 1fa34b5dfb8f50388ac6387aa6ad8672e333b0d5dfa3e725f2ef0308091a10b8n/aMirai
2025-03-05n/ash b1c84c538e3bb503b83e56ec36df6b1655121a7c02a9d423f3c5e3c34b457cd8n/aMirai
2025-02-11n/ash bac564a87ec8033f37f61127b976421fb3875bb1e7fc78c3f6350f4ee9226187n/aMirai
2025-02-07n/ash 52cf69deca0da7f759a1b4afcb74dae344ec5ab896625a3a0f6d778650a845dcn/aMirai