URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610350
URL: http://109.205.213.5/resgod.sh4
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-24 04:22:12 UTC
Last online:2025-09-09 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: redrabytes
Abuse complaint sent (?): Yes (2025-08-24 04:23:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:15 days, 22 hours, 39 minutes Bad (down since 2025-09-09 03:02:10 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-07n/aelf d9c3bdbfc3930340483c07ff809d21b3a70c431b4e93b0938c010a90bd629538n/aMirai
2025-09-07n/aelf 433adbda8c2a0477cf4b17d3202240e254e65453817162bb51d0c14569515e01n/aMirai
2025-09-07n/aelf e803f313d93366fab2fd9002b059ed150aa1cccb9fc4a7d704a0174bc2e1cc7en/aMirai
2025-09-06n/aelf 8434bd0fe9e761b1abec2e267b3e9508f263b2cd1ac147c9cfa1c7fc0a84be46Virustotal results 41.27%Mirai
2025-08-26n/aelf 235851ae257e8739c123fa5c2a8ab9035a69985a96eed60972803bad31954318n/aMirai
2025-08-24n/aelf 9876ca3a151a2fc18fe611e831804a427390cb27c28ad13395acb99a2413533dn/aMirai
2025-08-24n/aelf 50a80ef3eb825b0d0ab258955f442be15afe2545794104869e58cfef0b7a6c6an/aMirai
2025-08-24n/aelf b288ce5aae1c3c0e9fc125773894f458467d228a03e7b2de6db308de8fbfe7den/aMirai