URLhaus Database

You are currently viewing the URLhaus database entry for http://mirai.cinquento.publicvm.com/main_sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3440543
URL: http://mirai.cinquento.publicvm.com/main_sh4
URL Status:Offline
Host: mirai.cinquento.publicvm.com
Date added:2025-02-15 09:31:07 UTC
Last online:2025-02-16 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-02-15 22:41:04 UTC to u-abuse{at}ultahost[dot]com)
Takedown time:5 days, 3 hours, 49 minutes Bad (down since 2025-02-20 13:21:08 UTC)
Tags:botnetdomain censys elf fbi.gov GREED mirai link moobot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-15n/aelf d844fb6df57d4339e1d970d417b21b422466e64e0ed1c6d586d9d11ad093f151Virustotal results 43.55%Mirai
2025-02-15n/aelf 579ca2e8aa8e41d5cebdc07fd126e74163ffb67a30256b844f4c4d55d581e47cVirustotal results 39.68%Mirai
2025-02-15n/aelf e65f93170d6c105ff8a38016f52c39b9f06eca82342a4103c36dd8e19afe63c5n/aMirai
2025-02-15n/aelf 8dc69a364e939353b08349c4dbc36b48450123d1d50b154699e28bcb188105b8n/aMirai
2025-02-15n/aelf 9b0bfa7d3bede3d928e94de8e8d5abd9f1a2f3aee4cc1ee0da8c2a2a21487a93n/aMirai