URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623681
URL: http://158.94.209.216/sh4
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:12 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 71cf2bcec3f927abc59bb4a57e950a1685ce005380b6a2e3dad891788828dc07n/aGafgyt
2025-09-29n/aelf 21d53afe401a08cbb873a48fbbf5dce9bd7e994180de37a25176edcb03704e17n/aGafgyt
2025-09-29n/aelf 7854386b134d32ce937590c66ac7ab7ac96b908b368230ac730b39a99394993fn/aGafgyt
2025-09-26n/aelf b3c73f074ac991a64ba5f8e7c90781f2f13aa575a939ad2c35db91a0c3d81f17n/aGafgyt
2025-09-25n/aelf daeb57ceb398b726dcce63f54f3aa27ce01861e8b909e08e116b394481f574f7n/aGafgyt
2025-09-14n/aelf 574bd85b0b717f2c916326c6e53395e4eca61ae798487b721334bce0470d8bd4Virustotal results 51.56%Mirai