URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.66.32/wget.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3579487
URL: http://196.251.66.32/wget.sh
URL Status:Offline
Host: 196.251.66.32
Date added:2025-07-09 08:35:08 UTC
Last online:2025-07-25 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-07-09 08:36:15 UTC to abuse{at}nybula[dot]com)
Takedown time:15 days, 15 hours, 27 minutes Bad (down since 2025-07-25 00:03:33 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-19wget.shsh e8d20c029bc55bfd0f3666db04f91c3d918e2b1277d669f90430d5049ca7d2ebn/aMirai
2025-07-13wget.shsh ec92aba591e653b5004e972de1ae80c32a75b866c909aefc18f54d990545341bVirustotal results 27.42%Mirai
2025-07-13wget.shsh 068540494a1d92ba7fce68acf8197cac6cf34cc4a6bbb9aa21f78a97682492bcn/aMirai
2025-07-11wget.shsh 010ba2ee7ff600411e8db9407557395c7828819fd61bfd9ad2ecf623a8cac263n/aMirai
2025-07-10wget.shsh 4dfac6f519d130bc165c1af3a9d9197e8048525750ee4789def32eb04704648en/a
2025-07-09wget.shsh 8df3986c1c1391c6e7e765c2ceca28e0d4286a2edf54119d352b38d35ec2f583n/aMirai