URLhaus Database

You are currently viewing the URLhaus database entry for http://5.175.223.124/w.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3795926
URL: http://5.175.223.124/w.sh
URL Status:flame Online (spreading malware for 5 days, 9 hours, 48 minutes)
Host: 5.175.223.124
Date added:2026-03-14 15:42:09 UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2026-03-14 15:43:21 UTC to abuse{at}ghostnet[dot]de)
Tags:mirai link script

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19w.shsh 6887cfa51d87a3cc2393531076c5b7f2a0a2cd06d2fe9705c7b262e90fc26715n/a
2026-03-15w.shsh c12f337e79aec5b72849b9b1a707f28e745545a1a14b598d34abe637a180b967n/aMirai
2026-03-14w.shsh 1882df396998383613fa21485eb146feb59be3430cc57a12e0ad5ae1fe4d850dn/aMirai