URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.107.133/bins/psh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3791142
URL: http://196.251.107.133/bins/psh4
URL Status:flame Online (spreading malware for 1 month, 29 days, 18 hours, 46 minutes)
Host: 196.251.107.133
Date added:2026-03-07 00:02:21 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-03-07 00:03:15 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-18n/aelf 303bf1629f8a98593d5b774c3e42e86ae2c68aa981066c4995fbb2870c004dd0n/aMirai
2026-04-17n/aelf 38dad8f0d38d95d8ba435ae7a345bc095ec2850cd8f91103f12df690251a735cn/aMirai
2026-04-17n/aelf e78c1b31cb63d4a4e46a71105c4314555ff8673fc4a0f14a81a5c05b325a07c8n/aMirai
2026-04-15n/aelf c18a2e92cbf0a6fbe88d305f78a689c44f705fe474d9ea1166fd6c16f45d9aa3n/aMirai
2026-04-14n/aelf 3f2f3addbd402c4953731f0212b74360ec1aaa370f45f20df28b081d73f111aan/aMirai
2026-03-07n/aelf da5c870b9d7d7d4ca4f65f5a32af71627add436fd70568c0c72bf0462da45225n/aMirai