URLhaus Database

You are currently viewing the URLhaus database entry for http://207.244.199.152/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3604496
URL: http://207.244.199.152/sh4
URL Status:Offline
Host: 207.244.199.152
Date added:2025-08-16 08:22:16 UTC
Last online:2025-08-18 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-16 20:03:10 UTC to abuse{at}freakhosting[dot]com,report{at}abuseradar[dot]com)
Takedown time:1 day, 13 hours, 41 minutes Poor (down since 2025-08-18 09:44:35 UTC)
Tags:elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-18n/aelf ec360d88a2835d4c91ef7103e48492797269fa084913ecb728735a06d35afe6bn/aMirai
2025-08-18n/aelf 2d067c7bfaa629f7f26772c82a02140eec9052385d932da2a051b38dd4eb0401n/aMirai
2025-08-17n/aelf 35a80763c51c47a7d2b71a3f4888c988be308e4c00be430872933aa29bae76a3n/aMirai
2025-08-16n/aelf 98965ecd12ce871d2429bb64c64df92d086375c41c55e11c040375c3586054b8n/aMirai
2025-08-16n/aelf 238d20dec57b10942f17d6b808a087e23184559deb87b2e5af87ba63ce43b569Virustotal results 40.62%Mirai