bin.sh - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned bin.sh and returned a unknown verdict (score 8). The page resolved to 207.153.1.24 on US Internet Corp in US. 2 domains and 1 IP were contacted. 3 malware samples communicate with this URL (Mirai). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 8) · Confidence 11%
- Scanned URL:
https://bin.sh/ - Domain: bin.sh · IP: 207.153.1.24 · AS10242 · US
- Server: Apache
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 18 04: · subject CN=adhack.bin.sh
- Scan tier: fast · observed 2026-08-22 21:41:23 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from bin.sh. Each links to its full analysis.
- Mirai - referenced ·
28708524a0409fa372c828dfc817712c· first seen 2026-08-22 - Mirai - referenced ·
d45d025d4fc1bb11f1e88011b1da13cb· first seen 2026-08-22 - Mirai - referenced ·
0795e6fcc25cb34317d8190d1ad13258· first seen 2026-08-21
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Untrusted certificate (ERR_TLS_CERT_ALTNAME_INVALID)
Detected technologies
- Apache
Contacted infrastructure
- 207.153.1.24 - AS10242 US Internet Corp (United States)
Observed indicators
- bin.sh
- www.bin.sh
- 207.153.1.24
- https://bin.sh/
- https://www.bin.sh/
- https://bin.sh/motif/demonweb/banners/bloody.jpg
Questions about bin.sh
- Is bin.sh safe?
- The scan of bin.sh on 22 Aug 2026 reached no verdict either way (score 8). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with bin.sh?
- 3 analysed samples communicate with this URL, including Mirai.
- How was bin.sh checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bin.sh
Scanned on MalwareAnalyzer by Cyble · Open interactive scan