URLhaus Database

You are currently viewing the URLhaus database entry for http://195.178.110.204/s which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812302
URL: http://195.178.110.204/s
URL Status:flame Online (spreading malware for 1 month, 22 days, 6 hours, 37 minutes)
Host: 195.178.110.204
Date added:2026-04-05 07:00:19 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-04-05 07:01:18 UTC to dmzhostabuse{at}gmail[dot]com)
Tags:censys sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-25ssh ccf7ca42eee667916cde44e23576ceb7c00ab53146ccbdd5978bd465baa99be0n/a
2026-04-16ssh 2e66ab88f615f3b0fe6d874597fae654ed67c80b5ee56efe5aed5f1bf0511719n/a 
2026-04-09ssh 185b6d3f34acd1284f84b81993a4826f7251bbbe4030ce22f01c92f2d93e50a4n/a 
2026-04-05ssh 879a33fa51f1197f05f50aca4b5c934356e819fce6445dca6ee9a455422797ebn/a