URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.27/w.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3747933
URL: http://158.94.208.27/w.sh
URL Status:flame Online (spreading malware for 10 days, 15 hours, 33 minutes)
Host: 158.94.208.27
Date added:2026-01-01 10:00:17 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-01-01 10:01:13 UTC to abuse{at}lanedo[dot]net)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-10w.shsh 12ef71076e671f3c6823f1b05a4d62eefba6acc49fe48a921fc5f4b668e683ccn/aMirai
2026-01-10w.shsh 05bb46c2da318f9fd81b6e61aa5ba9c88d236e6665fb8d834e46ea6ed66207c8n/aMirai
2026-01-09w.shsh 1ab103878b7a16b80d439cf74a2e5d50c6e21414a1475471721d848d795dbec6n/aMirai
2026-01-01w.shsh fda714a2156ef936a25f24b3444f7d1fb0517ec4aaa7a019594b7e3ebb0f5ca4n/aMirai
2026-01-01w.shsh 59c52e9ec13aa8f1b48f28bf5a3ddf0d58b8ca2e0cb8a596a30557a535ba4cabn/aMirai