URLhaus Database

You are currently viewing the URLhaus database entry for http://194.38.20.199/p.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1046474
URL: http://194.38.20.199/p.sh
URL Status:Offline
Host: 194.38.20.199
Date added:2021-03-04 10:19:07 UTC
Last online:2021-11-30 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-04 10:20:05 UTC to vb{at}smartmedianetwork[dot]com[dot]ua)
Takedown time:9 months, 1 days, 1 hours, 13 minutes Bad (down since 2021-11-30 11:33:06 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-16n/aunknown 792818e88072aa5abb6bca9b28a675d33ee35d1ac4e151488df9983e8658b435n/a 
2021-06-09n/aunknown ede8fdb68d777efcc0538b465d640cbb2c061bd49461f76d65f68c135ff8bbb6n/a 
2021-06-08n/aunknown 122b5df883a0a1206487e793e530945abb318b5eb901d91f47c226c499ac8757n/a 
2021-03-25n/aunknown 2922121d8d017cd960d66ec5646ec63cd3e6671ceec36b18e5afb456d08fbd71n/a 
2021-03-13n/aunknown 72247d757fecb45f7a0619caa22873023e90cd087637db4401a26332ba0043f9n/a 
2021-03-04n/aunknown 8365cd4ebf9e14c518d571acc7e5592a873e5a78bb4b7d39b663c6f25fa1e500Virustotal results 35.00%