URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.69.194/router.zyxel.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3607070
URL: http://196.251.69.194/router.zyxel.sh
URL Status:Offline
Host: 196.251.69.194
Date added:2025-08-20 05:18:11 UTC
Last online:2025-09-11 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2025-08-20 05:19:13 UTC to abuse{at}cheapy[dot]host)
Takedown time:22 days, 17 hours, 22 minutes Bad (down since 2025-09-11 22:41:25 UTC)
Tags:ascii mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-23router.zyxel.shsh 69cb1979c3db09d9708ddb38236f74f620af90e4f9e9c56a0cbd77e065d7cdd8n/aMirai
2025-08-23router.zyxel.shsh 0e6fbbe09430717dd44c4719ccc184a791d0d1f27f5f457fc29d8ac309f54c02n/aMirai
2025-08-22router.zyxel.shsh 31be8265aea2d632bbca6e4d924e9070c87d770ed250c38a1fc4c174d15b5209n/aMirai
2025-08-20router.zyxel.shsh 3e47b3a535f5dca6b395e09cba27452e33e56b2c827eada547c59f8eda9cbe47Virustotal results 30.65%Mirai