URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.140.135/c.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3430689
URL: http://176.65.140.135/c.sh
URL Status:Offline
Host: 176.65.140.135
Date added:2025-02-07 06:41:08 UTC
Last online:2025-03-12 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-07 06:42:07 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:1 month, 3 days, 2 hours, 36 minutes Bad (down since 2025-03-12 09:18:09 UTC)
Tags:mirai link sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-06n/ash dc483e17c69e218cda5cbbd7a342b10707de8fc27daabad64ace825705998f08n/aMirai
2025-03-06n/ash c3252c2dfa3ffbb915ad59f1b620d7273caf598392360697b923114991f318d1n/aMirai
2025-03-05n/ash 01cc4546042b6cb240e691f5c2fb3b27874f172d3fc8158aebb720d35d6e9cd4n/aMirai
2025-03-05n/ash 2c054d1977d63d087d06e5e505396605d9a37d5168bd730fb3c5dd8decf7a15an/aMirai
2025-02-07n/ash f05585cc24014f0666f625b2916089e8182f3185a3d083b74f445fd39064b6fbn/aMirai