URLhaus Database

You are currently viewing the URLhaus database entry for http://www.teamc2.duckdns.org/bins/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3722821
URL: http://www.teamc2.duckdns.org/bins/sh4
URL Status:Offline
Host: www.teamc2.duckdns.org
Date added:2025-12-02 05:05:22 UTC
Last online:2026-01-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-01-22 14:17:14 UTC to paul[dot]vangool{at}hyas[dot]com,pvangool{at}gmail[dot]com)
Takedown time:1 month, 21 days, 12 hours, 37 minutes Bad (down since 2026-01-22 17:43:58 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-09n/aelf f2789e55ad0a1edfced788de223fda7ad57103767101ead2508cb1b2b3b4f151n/aMirai
2026-01-03n/aelf 8937849172db05d08b470bd11d922c3c9f018485f5c4981573af5d768c019e49n/aMirai
2026-01-03n/aelf eed6cd09a0207f8b60ed9b55469c63d417e53960790b16ecd193e07df460e098n/aMirai
2026-01-02n/aelf 4f80e922400955ac6b74132e7f9ec15a68f5d08a1d2ce2938933fb0b8124d2adn/aMirai
2026-01-02n/aelf 6389e9b4f74f82ae07e96e08e94658d707eaf6e2ce83820a2932c38bed98d901n/aMirai
2026-01-01n/aelf 87c24fd083fba2e6dafab0a4ca37e72fe2d411ac3645ca65b03e1b71a8beba06n/aMirai
2026-01-01n/aelf a2a9ba87bb209afbec2d8d3915123b442629bd1b3c1f83adf3c62d8dccaa7245n/aMirai
2025-12-31n/aelf 5fa0c525f52dcbc0288034e7f89540c1ebc6b4c0c1b40f5cb4592dcdfa05c93en/aMirai
2025-12-31n/aelf e4b49524b06dbe7314c39a441bcf797f3c01c8c38eca0d1391fd3106dda4fbdan/aMirai
2025-12-30n/aelf 11c479438753c2af47ce7d28e40d0b175b9eab6a426c9808bd45f8aedc299b1cn/aMirai
2025-12-29n/aelf 12a37788418b32ea3def214229f7fae49f2d69a1952c9c892acaf12940a9966dn/aMirai
2025-12-29n/aelf 3123bbb8f89c98fb4b134ab3cbac14eff2cdea301e94b52858bbf3aa8b993052n/aMirai
2025-12-28n/aelf 1fa07782e326932ff49a59a31ed3f039cd8b978b73e9623f2ef801e8d60b55f2n/aMirai
2025-12-27n/aelf b1b62501cef37dc78003e4b888bcd1a7f2111a3254487a1ce8869a5ee5da60cen/aMirai
2025-12-27n/aelf 588fd3c4b223f1c3a719e77f426533a0e0866d5e572125dabb97cf1e3b740b41n/aMirai
2025-12-26n/aelf f602961b69ff4be169735423d69bf956d034c24adf45fe63091e55ec0a7b9d95n/aMirai
2025-12-26n/aelf c047c8faa1e4a6ae2398e78f2ea09fcfc50ca161df14b848857816ddeaacdb5an/aMirai
2025-12-26n/aelf b243105114d61c1ad3403606657d8afad33d35732956773afdf6e4f6d679a476n/aMirai
2025-12-15n/aelf 14d4af82d5566a2cd3a4f81aef840a0f5d4c6f62f95eee5d7ae9e838bccabdf3n/aMirai
2025-12-13n/aelf 69093ef0bd87f2e329863cd4d9f682d04e05d22e8f075c71d8b9bc56cdcca073n/aMirai
2025-12-13n/aelf 313dc0c6aff5aedde146233d5e85adbb2ed29521b6d90534333610d42ada04c7n/aMirai
2025-12-04n/aelf b1eccaad4aab582b888afd3ff0964c870aa22c01c6c848a5402f42f7461eee7fVirustotal results 53.12%Mirai
2025-12-02n/aelf 4c047ad8042d6ea8e338e77b133cdf4be8ded4734ba150c3bc2865812dca2a0fVirustotal results 59.38%Mirai