URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/shk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3620246
URL: http://109.205.213.5/shk
URL Status:Offline
Host: 109.205.213.5
Date added:2025-09-08 16:29:07 UTC
Last online:2025-10-10 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-08 16:30:13 UTC to abuse{at}razinetwork[dot]com)
Takedown time:1 month, 1 days, 18 hours, 39 minutes Bad (down since 2025-10-10 11:09:17 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-02shksh 5c0bd85c53739eb4cef69bd887027e1b6bc008bbef34a794caece296615e7c27n/a
2025-10-01shksh 704acd2ef9a9598bdb1a3f2894cc94af05ceb05476b3786f3fbb231ab4a893c9n/a
2025-09-27shksh 86a2672afe9d6fdf22e77338945eb7f7885eedc80569afce02bc0c8a718cd6c9n/a
2025-09-21shksh 50ccd7cd274ea9f849c4d831f50aa0ffdcf4708594aee8b3c8fce377b384ea38n/a
2025-09-15shksh a006059abe53e52d80d5c171a1a23f1220d78804022464293be79ef4388bd35cn/aMirai
2025-09-08shksh 654719251e075e9a717afc08eaf315975d3530254fb88c172a123f686e81d9ebn/a