URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469831
URL: http://154.205.128.91/sh4
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:09:05 UTC
Last online:2025-04-16 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-03-06 21:10:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 51 minutes Bad (down since 2025-04-16 15:01:47 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf 43262af93a9b0333ecb56f6e80c61b73246bf6f24169f05c4c782ad11c103b4an/aGafgyt
2025-04-14n/aelf 1e27d80628ff82735b1efb58c7ac743f7ecf533b6de2074d4cc5a2bdc5276ab8n/a
2025-04-14n/aelf 22b1abe1ab8e79090fd59bd2fc0c447dc2acc579dbe242613f45726a7927de54n/aGafgyt
2025-04-12n/aelf 862c5df20457b3bc2f9f1e02bd1103ea2db1e1f2d517eafc2321a135ba8012adVirustotal results 38.10%Gafgyt
2025-04-10n/aelf 14c99206fd4d21983ec860d49f370fa1c707488e04ae7a1227a3d3b0d706c91eVirustotal results 38.10%Gafgyt
2025-04-06n/aelf cf41ecffccd976b45d5939432dc07b2e06ca5a65ba834fbea992b53241aae9b5n/aGafgyt
2025-04-02n/aelf 26b00fffb4dcfdf0e6531bc3409c6c14755cd8673c66036b202ac15bc51561d6n/aGafgyt
2025-04-02n/aelf 7ce50411aaaa58648c44522eae656de97c804bb42031c5111a1d586d3ae6b630n/aGafgyt
2025-03-29n/aelf 63f89d68babd282f03fa167642572e1b474b9b5f54bc84229d0c7cb447c9480dn/aMirai
2025-03-11n/aelf 0e7eb62f94c35407d91b9a0cab4b733690ffc440dc35caef95cf58be7517931en/aMirai
2025-03-09n/aelf 687ca2ff1a9e1f4f579a77db0275ffcdb1660e2703f2bf37b1fbe17b6a09227en/aMirai
2025-03-08n/aelf 49d025bbbc67c743d6749817f9320f663d533aa049439b16b9c740bfafd18c16n/aMirai
2025-03-06n/aelf 36b7e370415f133bbfdb69086ea70a0fc379e181013f61d433bddd50c4a04427n/aMirai