URLhaus Database

You are currently viewing the URLhaus database entry for http://2.26.136.128/twget.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3891894
URL: http://2.26.136.128/twget.sh
URL Status:flame Online (spreading malware for 27 days, 12 hours, 17 minutes)
Host: 2.26.136.128
Date added:2026-07-26 12:19:26 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-07-26 12:20:34 UTC to abuse{at}vdska[dot]online,ripe{at}interlir[dot]com)
Tags:2-26-136-128 mirai link sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-07twget.shsh f2e2ffc024ab99eb49fa207756481aa80713398142f30888aebace5706909b36n/a
2026-08-06twget.shsh f2291321df3b93aed41359a2f5f3fa22bf4a16da1a13343cc3daca9657fbac6cn/a
2026-07-31twget.shsh cac00f4de01f0b46d9646e425ae88152df96d7393c98099f2a373e86dbd56176n/a
2026-07-26twget.shsh d079a02683cde96446dae0624843f3a0ce1641a26a75083b9aef4cc8b892343an/aMirai