URLhaus Database

You are currently viewing the URLhaus database entry for http://46.8.78.55:8080/systemctl/bin.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3847401
URL: http://46.8.78.55:8080/systemctl/bin.sh4
URL Status:flame Online (spreading malware for 7 days, 2 hours, 50 minutes)
Host: 46.8.78.55
Date added:2026-05-15 15:49:13 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-15 15:50:18 UTC to abuse{at}cloudbackbone[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-22n/aelf 99b762dd561d9f183f06d4bb8e097f86e00beb3a378ceafaff02672613bf64d5n/aMirai
2026-05-22n/aelf d1343b41c2fbfb24d438b4ddb58017aeeb9cb4ca03bba3409b633000b972859en/aMirai
2026-05-21n/aelf 4fcf278fd91fea5105c1603a7d09d1528cccb00fd07ae4ed1b029b5e2a0a7d45n/aMirai
2026-05-21n/aelf d12bf20479814b3957660580dc02b9c585bf99d4c6306c14dd41eb5b22a5275fn/aMirai
2026-05-18n/aelf a94da43bdbb1fcdee40090d5db164c836ce7158276cf31394152d5ff7106ab93n/aMirai
2026-05-15n/aelf a41ed253774c35c72278881b53779f9fa14ab5cb06d092b092baa5f77ddc1e60n/aMirai