URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.133.58/dvr.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3574806
URL: http://154.205.133.58/dvr.sh
URL Status:Offline
Host: 154.205.133.58
Date added:2025-07-03 11:42:05 UTC
Last online:2025-07-23 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-07-03 11:43:11 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:20 days, 12 hours, 7 minutes Bad (down since 2025-07-23 23:50:28 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-22dvr.shsh 4803efe03f729d3d5bb3cc181f09c85f59b15cf28ba97229f476ae7b03535efen/aMirai
2025-07-21dvr.shsh e5b3bd17048e3b9e7b69ec81f900cf63144b705de7a8cd9dd3bd0637c6b3b291n/aMirai
2025-07-20dvr.shsh d752722edb1ffe46a0015d4de4f03bd245bf64b2d41b1a702a057e4661d3e8een/aMirai
2025-07-08dvr.shsh 8a780c4676f45ece3e84ee0b257596fdf8c2a9199ecfa6113fac2e909164d316n/aMirai
2025-07-04dvr.shsh 8575be3cabec97560dfc0892d33a7536d5b88c98674b01c2a4ea4aba924e9ac5n/aMirai
2025-07-04dvr.shsh e64124e337da6f27f46d7bb35cfd538029a52a4c9207c9a9d4f5342092edc1ben/aMirai
2025-07-03dvr.shsh 39e74d6cbe1da1a800ef0abcf9c7d9177a9982d58898356c73c0a74c833fce02n/aMirai