URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.56/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3609801
URL: http://45.125.66.56/sh4
URL Status:Offline
Host: 45.125.66.56
Date added:2025-08-23 07:35:41 UTC
Last online:2025-09-28 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-23 07:36:35 UTC to admin{at}serveroffer[dot]lt)
Takedown time:1 month, 5 days, 20 hours, 22 minutes Bad (down since 2025-09-28 03:59:29 UTC)
Tags:DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-02n/aelf ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5Virustotal results 29.69%Mirai
2025-09-02n/aelf af0fb9d161fed8081df37d21e77efdab7faa16c1907e8b85a0bad038a156c643n/aMirai
2025-08-31n/aelf 56cef38a5fa446692180dfcfe8c27086cca1a3e06b2650ed0c7a0b3d6b58f545n/aMirai
2025-08-30n/aelf b7f6888a3679a468d0a05c7c72d6d989206abf5c7ae2eac37c048fbe47132c82n/aMirai
2025-08-28n/aelf eae3cea82802b1518ba75ed343358f2e79d3f2ef571090d55bc278d45fe4da0en/aMirai
2025-08-27n/aelf f29fb927e1f33b7ce639e40bc4b08a5da54eaa96828795c1755f3243f1448797n/aMirai
2025-08-26n/aelf 3f1de6f09bb8daeedbc2e2f2f70adee3bb3680afe5cc4c4103f9a2b580d294een/aMirai
2025-08-25n/aelf a095d8a9638108662439961ec118220eafbb3a88bde6711d6c0010e379ef999cn/aMirai
2025-08-24n/aelf 65c6d82eeb267796fe9f103ca004945d4d1e39c1a4688c8bcf3f9da07d39481bn/aMirai
2025-08-23n/aelf 4a169934f11dc2e47975db7e2011de96a54dfc5fb6693607e04eeb7b2c06709bn/aMirai