URLhaus Database

You are currently viewing the URLhaus database entry for http://194.38.20.199/ex.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1046504
URL: http://194.38.20.199/ex.sh
URL Status:Offline
Host: 194.38.20.199
Date added:2021-03-04 10:28:04 UTC
Last online:2021-11-30 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-04 10:30:05 UTC to vb{at}smartmedianetwork[dot]com[dot]ua)
Takedown time:9 months, 1 days, 1 hours, 6 minutes Bad (down since 2021-11-30 11:36:25 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-16n/aunknown 57ffe041cc04e553e5af915d8db0030446f130c8df560bcd3947a9584f23067an/a 
2021-06-09n/aunknown 56ac2321e481708ea72e2bf7710e66c3455afa729b24f6a6ba9065ae0cca8fb3n/a 
2021-06-08n/aunknown 8b02eb1dbfa4f62f37ac9f9c486b0f3fbbedff0119b7a8aecef11fb92bfcc7b2n/a 
2021-03-25n/aunknown fcf18a5e16c2aae8725dc270d516a1084f8b61375cbaac1b4648e88230ec3916n/a 
2021-03-13n/aunknown 91fb662db516ee052055185ea67e789184fa8ab2e3c63f3f4e832ca85f17b1a6n/a 
2021-03-04n/aunknown 228ec858509a928b21e88d582cb5cfaabc03f72d30f2179ef6fb232b6abdce97Virustotal results 35.00%