URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/ssh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3620256
URL: http://109.205.213.5/ssh
URL Status:Offline
Host: 109.205.213.5
Date added:2025-09-08 16:29:07 UTC
Last online:2025-10-10 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-08 16:30:14 UTC to abuse{at}razinetwork[dot]com)
Takedown time:1 month, 1 days, 18 hours, 35 minutes Bad (down since 2025-10-10 11:06:02 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-19sshsh 606fd541d4d782d04ee1b38bc142854eb5930ba5588a507592f18795f0beed61n/aMirai
2025-09-10sshsh 55f3c135a5e84c4e6bc718fc4ddbb1e9098d6cae7aaac9ea5f6444883c9fad77n/aMirai
2025-09-09sshsh 9e00364c7b9cf4e6b40622632d4fe6e38ad863c8bcc053410e0d527dcee3efa2n/aMirai
2025-09-08sshsh 2adb187fa20993925bf54526a2f48b105b33455de7ffda30a81fba0b2503dd70n/aMirai