URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.152.84/sdxkzX_UXA229x.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3743068
URL: http://192.227.152.84/sdxkzX_UXA229x.sh4
URL Status:flame Online (spreading malware for 17 days, 21 hours, 50 minutes)
Host: 192.227.152.84
Date added:2025-12-25 07:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-25 07:35:15 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11n/aelf c2c21ee47f5f90c68b992bedae3b57314257e435ebbd61febb09d35547b3ee99n/aMirai
2025-12-27n/aelf 6e3131a8cc91c2b34bed30ceb7ff3544a6ed824892cf5d8451408c8ec1e94ed0n/aMirai
2025-12-25n/aelf 7501f714f4c5c7ec1efc47ba26305c02859416ad276d01090665117a2183065bn/aMirai