URLhaus Database

You are currently viewing the URLhaus database entry for http://185.39.207.117/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3502740
URL: http://185.39.207.117/sh4
URL Status:Offline
Host: 185.39.207.117
Date added:2025-04-06 10:01:31 UTC
Last online:2025-04-17 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-04-06 10:02:25 UTC to abuse{at}globconnex[dot]com)
Takedown time:10 days, 21 hours, 38 minutes Bad (down since 2025-04-17 07:41:21 UTC)
Tags:gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf 1e27d80628ff82735b1efb58c7ac743f7ecf533b6de2074d4cc5a2bdc5276ab8n/a
2025-04-14n/aelf 22b1abe1ab8e79090fd59bd2fc0c447dc2acc579dbe242613f45726a7927de54Virustotal results 38.10%Gafgyt
2025-04-12n/aelf 862c5df20457b3bc2f9f1e02bd1103ea2db1e1f2d517eafc2321a135ba8012adn/aGafgyt
2025-04-10n/aelf 14c99206fd4d21983ec860d49f370fa1c707488e04ae7a1227a3d3b0d706c91en/aGafgyt
2025-04-09n/aelf 058f604021be11c80af908d7c72bee6ca5f54eb254748ed57c56e5711c2e06e7n/aGafgyt
2025-04-06n/aelf cf41ecffccd976b45d5939432dc07b2e06ca5a65ba834fbea992b53241aae9b5Virustotal results 37.50%Gafgyt
2025-04-06n/aelf 2cec1349f963ff8ceb42fc5dcda5be99667326e25d387482f7e11c38b91ed786n/aGafgyt