URLhaus Database

You are currently viewing the URLhaus database entry for http://81.88.18.108/bins/shadow.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739067
URL: http://81.88.18.108/bins/shadow.m68k
URL Status:flame Online (spreading malware for 3 days, 9 hours, 30 minutes)
Host: 81.88.18.108
Date added:2025-12-21 12:35:21 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 12:36:18 UTC to abuse{at}dogado[dot]de)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-23n/aelf 5442e5301eab8ab38d0957494067d4b1e5f0df7123945e9fc2a19ca0e82eb502n/aMirai
2025-12-21n/aelf 4e35f9129331437c0b687a7ea5b7b1c800f0a8034e846aaf1f881ef5fe443d8an/aMirai
2025-12-21n/aelf fc20dc48a3bbd0ae4736e127f4af8ebe93991a553c60a3b13146bfe1923c9552n/aMirai