URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.141.182/main_sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3494846
URL: http://176.65.141.182/main_sh4
URL Status:Offline
Host: 176.65.141.182
Date added:2025-03-29 15:22:06 UTC
Last online:2025-04-21 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-29 15:23:07 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:22 days, 19 hours, 34 minutes Bad (down since 2025-04-21 10:57:17 UTC)
Tags:censys elf mirai link moobot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-16n/aelf b5ec111066098220bd6a79c77c95c5390651ba063cfd416051742093b6729341Virustotal results 57.14%Mirai
2025-04-09n/aelf cdf6fbe43c5334e2664b62de97e7cc016ea6791496bdc465ab1facf880a2e818n/aMirai
2025-04-07n/aelf ce3cc60206cdd5287c3c4f3be836105a5836ad3915cafecdc250081553e39eb0n/aMirai
2025-04-04n/aelf d13ea0489bbc2ff2ef5247566d520f5f7c2ebd920aac894b56c8795e5ce4c1dbVirustotal results 57.38%Mirai
2025-04-01n/aelf 205d32ef55816d706d9a10af5fc87cebbfe5c9e9041786179ac110b774a4d1fdn/aMirai
2025-03-29n/aelf 799231674af323aebecbc3c0a8b5845b957ea77597d2a313829661f515660f99n/aMirai