URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.144.18/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3502003
URL: http://176.65.144.18/sh4
URL Status:Offline
Host: 176.65.144.18
Date added:2025-04-05 14:08:05 UTC
Last online:2025-04-21 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-04-05 14:09:08 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:15 days, 21 hours, 23 minutes Bad (down since 2025-04-21 11:32:30 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-19n/aelf 62a35f2908ff62726a82027bb143bffb06cccebbf78648cefad288cc5e8566dan/aGafgyt
2025-04-12n/aelf 38b90286a9da96d9eb10f3eb8a509f5840d058f55107c0a76978767ccb4fb9e7n/aMirai
2025-04-06n/aelf 7b6229edf2bb89df853b704eeae31faf73386a59d72eda274e9865a91d14d604n/aMirai
2025-04-05n/aelf 038fdbb886081dd632ba12e09c3b4e1bcd6ee487984b56824c5da940e6b74ee5n/aMirai
2025-04-05n/aelf 971b04caa667c0f2a92bb34273ff0ff90bb6e2e2464ea0ceae14347e335d5156n/aMirai