URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.115.36/giga.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3594185
URL: http://196.251.115.36/giga.sh
URL Status:Offline
Host: 196.251.115.36
Date added:2025-08-01 12:06:06 UTC
Last online:2025-08-09 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-01 12:07:18 UTC to abuse{at}nybula[dot]com)
Takedown time:7 days, 17 hours, 29 minutes Bad (down since 2025-08-09 05:36:25 UTC)
Tags:gafgyt link geofenced mirai link sh ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-03giga.shsh d1cc2ab9ba5338df6b6eb6d7010eb64ee9d642fdb6a6281fbb21f16a29ae57c7n/aMirai
2025-08-02giga.shsh 053b7a1cfa02b3689216af734df0e9eb5dbfa0ebf9df53105021079b51586b24Virustotal results 61.67%Gafgyt
2025-08-01giga.shsh 3f0be4730da078e8bde3bc8a98c8cfbda1771a1df293575348734e16d45557f6Virustotal results 59.02%Mirai