URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.236/nz/nz.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3887338
URL: http://41.216.189.236/nz/nz.sh4
URL Status:Offline
Host: 41.216.189.236
Date added:2026-07-16 20:38:35 UTC
Last online:2026-08-04 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-07-16 20:39:28 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:18 days, 22 hours, 33 minutes Bad (down since 2026-08-04 19:12:30 UTC)
Tags:elf mirai link opendir SuperH ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-04n/aelf bd27d42373839562cab73b13a1a82b78ff151aaee3576d7799364f81b3ea5357n/aMirai
2026-07-26n/aelf 6d02686fc6972df21f925384d9304ffacfcdc1f9d6aa58f3dcf074f90ee284cbn/aMirai
2026-07-22n/aelf ebdc4f10d937bec20ad9234057e4b508a1d5f0a05321e087b48cb582f9a1c016n/aMirai
2026-07-22n/aelf aebe6c8a3c3a65159a761b6b67f7b9c3c5d070188f7fdf469c9ead6e125667a7n/aMirai
2026-07-21n/aelf bf237640d3c51687df288217abc2b25d7d43ea81780323b94a39b000f4bcd3cfn/aMirai
2026-07-17n/aelf 815d37f2c17fbed0d44554177fc338f577901fecf43e101b8809b5540777095dn/aMirai
2026-07-16n/aelf 1e45c6d4f8dee322386220bc10100f227a0c327a3938b9eae877c74ec37f1e71n/aMirai