URLhaus Database

You are currently viewing the URLhaus database entry for http://94.183.232.247/CRY.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3860411
URL: http://94.183.232.247/CRY.sh4
URL Status:flame Online (spreading malware for 5 days, 20 hours, 35 minutes)
Host: 94.183.232.247
Date added:2026-06-07 15:49:21 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-06-07 15:50:16 UTC to abuse{at}cloudbackbone[dot]net)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-12n/aelf 87218d3a50595e89c351f16eea6b4e3c5dbb6f1251fe2ca0369493baa46f7556n/aMirai
2026-06-12n/aelf bd9f811dbdb28a9aefd9dcbf192a1cb4bf1a98b86d34dbaf94b19bef00e1635an/aMirai
2026-06-10n/aelf 625881352b249686bd492871f96656d009d93e96b6a3cc9f9c43ee8cbe0f815bn/aMirai
2026-06-09n/aelf 4ee744704952c046ab51979d57a8477344c0a600dd0c7812c084846bf7584159n/aMirai
2026-06-08n/aelf 03920e66dec7dfd159e118fdcd06264f6e53283bc15cb8ccfaed83737a7a8231n/aMirai
2026-06-07n/aelf 38679f84b82e188affb462c17e50e5b352ca53f469b7424473bfdd0da8afcb6an/aMirai