URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.141.49/1.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3657447
URL: http://176.65.141.49/1.sh
URL Status:Offline
Host: 176.65.141.49
Date added:2025-10-05 06:34:18 UTC
Last online:2025-10-17 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2025-10-05 06:35:23 UTC to abuse{at}silverstreamcomms[dot]com)
Takedown time:12 days, 1 hours, 50 minutes Bad (down since 2025-10-17 08:26:13 UTC)
Tags:mirai link script

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-171.shsh c552ccf532f96584fd9e4923ebcd2bde0f0b8587bf633c05135cee27ebeb79e7n/a
2025-10-141.shsh 9ee5066a1854ee15278b55e0a4cf9c58c2446f0f4599d1de85202c2341026bbbn/aMirai
2025-10-131.shsh bf1e49c7a7d5e451eb8280d36d465bc8782aef93b67606bb54982152c815aa82n/aMirai
2025-10-111.shsh 9b25b603427438fe93e5a6851c94cf877f4279dd093882c8e02189aa195d9d31n/aMirai
2025-10-101.shsh 8a2880ab70300e517b82d6aebb562ea7c0d6b9c1214484a59d6c2a186d77ffc7n/aMirai
2025-10-051.shsh f88aa064da17427cee044401a23918bb616950b2a1c9efb2bea5be89265aa0c6Virustotal results 53.23%Mirai