URLhaus Database

You are currently viewing the URLhaus database entry for http://31.56.209.222/zero.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3857198
URL: http://31.56.209.222/zero.sh4
URL Status:Offline
Host: 31.56.209.222
Date added:2026-06-01 20:46:10 UTC
Last online:2026-06-20 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-06-01 20:47:11 UTC to abuse{at}swissnetwork[dot]io)
Takedown time:18 days, 11 hours, 52 minutes Bad (down since 2026-06-20 08:39:29 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-10n/aelf ea12a603f6f09b6163043aa356c1ec01193ea6f44c6669df5493ab3ffb503472n/aMirai
2026-06-09n/aelf 4584054446d0e99b8d13dfceb60eb3971604a497d5932af5b8f1ccfefe988d01n/aMirai
2026-06-07n/aelf bcb9245aaf4ab658224b2a860ce323083df75d4c3b22acc3ab9441215da2ac5dn/a
2026-06-07n/aelf ff665cca180266989960b332e8098b577b2d69e7e60b73f66002f857e33993ecn/aMirai
2026-06-06n/aelf 4968752e7952ae7c4df1670c272ca724f4bd1936c1e1ff5da98294dcbe6ace74n/aMirai
2026-06-06n/aelf e7b04c7c71e0a6c06b2da2b421810c5b5bcf1b7d198eff0345947d3a41575d9cn/aMirai
2026-06-06n/aelf 9a6fd15ef798e77c8e2266e32e3926f23faaf5f247bcfd081040c9e8b8fe702bn/aMirai
2026-06-01n/aelf 4ac01c402b80fd4c26683df46c9b2a05e47662219064d102ba99643ed5010e5fn/aMirai