URLhaus Database

You are currently viewing the URLhaus database entry for http://151.242.30.13/Mercury.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3716953
URL: http://151.242.30.13/Mercury.sh
URL Status:flame Online (spreading malware for 14 hours, 26 minutes)
Host: 151.242.30.13
Date added:2025-11-26 06:57:09 UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2025-11-26 06:58:15 UTC to report{at}abuseradar[dot]com)
Tags:mirai link script

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-26Mercury.shsh 2f90659f6a09f0a6ba5fc1b59d0c0f406330fac1bdafce63bc4f4e47164f52e7Virustotal results 60.00%Mirai
2025-11-26Mercury.shsh d5de67c5e0673aef41efd24208e43899641c7bb5a90c1c2d3dce85465587f281Virustotal results 62.71%Mirai