URLhaus Database

You are currently viewing the URLhaus database entry for http://report.504.su/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3742470
URL: http://report.504.su/sh4
URL Status:Offline
Host: report.504.su
Date added:2025-12-24 13:36:21 UTC
Last online:2026-01-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-24 13:37:17 UTC to abuse{at}lanedo[dot]net)
Takedown time:20 days, 17 hours, 47 minutes Bad (down since 2026-01-14 07:25:01 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-14n/aelf 56e767ebfba30891da28d6e43c705af1c050edb65eea0843364f5766cb5d8baen/aMirai
2026-01-02n/aelf f7e3a6d9ca890acde5b1a3f219c693274fd0259384238f7cbc2044d262902238n/aMirai
2026-01-01n/aelf 9553152b82de68774432016553a3073ca176666d02206e1469c419e64b6bc08cn/aMirai
2025-12-31n/aelf 345d51aa0e2db550d1ed2eff40504da56c5f2371403dfc6a5c383f0cb0de2246n/aMirai
2025-12-30n/aelf 42e4f4fc464dfa9b63bcdc48a28c5cbc0b96ece66551ba909cd56686cdad569fn/aMirai
2025-12-30n/aelf 647e6546ef3d1473ae7a8298bb5bed1408b01a30b84b692be01d1e55eb30acb0n/aMirai
2025-12-29n/aelf 5bc881ba00ef3da272a1c822c6016b3ed3e29a0a2b8bdf8c681fe87aeb93643bn/aMirai
2025-12-29n/aelf abdb1b4a4d103d5d5a7704958be79d2c71fad3c870c858d2bee093156fbb557bn/aMirai
2025-12-25n/aelf 1225df584e4052ab709cb869cce98a0f66042d4ac5639d6c000a37c358b2211bn/aMirai
2025-12-24n/aelf 41dc136e24334d833ed3e59f3b795c4aece5a4005f37be3cf44e4dc1c00ea06dn/aMirai