URLhaus Database

You are currently viewing the URLhaus database entry for http://chanchanmiraixd.duckdns.org/all.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3766760
URL: http://chanchanmiraixd.duckdns.org/all.sh
URL Status:flame Online (spreading malware for 3 months, 0 days, 5 hours, 34 minutes)
Host: chanchanmiraixd.duckdns.org
Date added:2026-01-31 17:10:20 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-04-27 00:36:11 UTC to abuse{at}neterra[dot]net)
Tags:botnetdomain mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-29all.shsh 289a65cd34035c522e456140bca2c5fdf6ad0d1afabc446dcda7fa528dd97b09n/a
2026-04-27all.shsh b4d75fc2d01f2f616ceb8f41ab1b2d23addcf42933c49a3e5578ff181ff7ad5fn/a
2026-04-27all.shsh 442f2564c9fabc4e76bd4b80b581d7c301a81d9c484fab201364acf8c471be42n/a
2026-03-21all.shsh 490f62778713185be4ab4ac38ee3738283a3e9442be92d11a436774b4f7c4302n/a
2026-03-11all.shsh 0c55f2a946b94ed32f57442ad1476a9eac57f28be75c345c5b2db1964b445793n/aMirai
2026-01-31all.shsh d0e064c4cc6ea3015ee06a5374b7a5d161c142b6a90afc2b67ae9a355743aa91n/aMirai