URLhaus Database

You are currently viewing the URLhaus database entry for http://194.38.20.199/t.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1046475
URL: http://194.38.20.199/t.sh
URL Status:Offline
Host: 194.38.20.199
Date added:2021-03-04 10:19:08 UTC
Last online:2021-11-30 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-04 10:20:05 UTC to vb{at}smartmedianetwork[dot]com[dot]ua)
Takedown time:9 months, 1 days, 0 hours, 59 minutes Bad (down since 2021-11-30 11:19:17 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-16n/aunknown c57a1707f8d75abe56d21b0c8b0d732f07fbf4b0687fce91683950674fd87f0fn/a 
2021-06-09n/aunknown 75476220388978e6c1fee32edf852ad4d661e195946aaf844bd1bad80172eb78n/a 
2021-06-08n/aunknown 0b96781431bda4c68f7757e16ac7b191dc489bb65badbbf464ec325f2afc2d0dn/a 
2021-03-25n/aunknown 2b0ca493100cbde8d40b3d8f0eeb5db78ebbc5dfa1b9882d0b087dddc475db5bn/a 
2021-03-13n/aunknown 8004c07c064fbd7cb4f1100bc60cce1c39d294e6bfeca8b573bf671af9e9188dn/a 
2021-03-04n/aunknown b3074de723c55cb6be34fe8c7bb4b340a473cd52d813017be8d978efdeff7943Virustotal results 35.00%