URLhaus Database

You are currently viewing the URLhaus database entry for http://disrupt.anondns.net/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3859713
URL: http://disrupt.anondns.net/sh4
URL Status:Offline
Host: disrupt.anondns.net
Date added:2026-06-06 10:55:11 UTC
Last online:2026-06-13 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-06-06 10:56:11 UTC to abuse{at}ghostnet[dot]de)
Takedown time:6 days, 15 hours, 54 minutes Bad (down since 2026-06-13 02:50:50 UTC)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-12n/aelf 5dca7ff5f05844fc96d42d3be4591a4fe4a148472c9d13cd31920634c0b5ef2en/aMirai
2026-06-12n/aelf 765745b79847886e94f8ec77f8ae810a3dddb5db3797af982b93886ebe875d89n/aMirai
2026-06-12n/aelf b21f7d8ab483ac5c6c6580cb54d0bdbd1a2c443a1bef57d162d5c092b75496ben/aMirai
2026-06-11n/aelf bda8d6766190639818b504be346cedf6d7b59a618a0395816d59be527287a1c9n/aMirai
2026-06-10n/aelf 8e51a36bae76aacbe6b4f33494e90fce1356f36e587b6a989fb51259226b3eccn/aMirai
2026-06-10n/aelf acddf2ffc4b58073a1a5ebf0b42eac18d7896a60b7dd406cd7b84493011b6426n/aMirai
2026-06-10n/aelf 11a9a9abebf986f0549e938b4eafac42a8b37e61b32fc8404edeefdfa14a1fedn/aMirai
2026-06-10n/aelf ed2bc52ee93c26c698e08759f1334d2f39325df8956b0136d38f06cd5be238f9n/aMirai
2026-06-06n/aelf d66fce565de64d2c8cc970e357c7e0eef3dbd930fb4016cec469ff50c1112c2en/aMirai