URLhaus Database

You are currently viewing the URLhaus database entry for http://213.21.229.201/bins/nova.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3735615
URL: http://213.21.229.201/bins/nova.sh4
URL Status:flame Online (spreading malware for 7 days, 0 hours, 28 minutes)
Host: 213.21.229.201
Date added:2025-12-17 18:18:28 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-17 18:19:18 UTC to abuse{at}vernet[dot]lv)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-23n/aelf 837d1ff6922f7db42f674c7b1d53913256a825b14277f0ac0b1c1d506857d9fan/aMirai
2025-12-18n/aelf 31fccf28792b9b8172af31b06386fc8f7a5cc7d73f218e48de1efac83964549fn/aMirai
2025-12-17n/aelf ee8c004a426483e15a908c8050807e90826107c0de312a72564b3958f255e391n/aMirai