URLhaus Database

You are currently viewing the URLhaus database entry for http://194.38.20.199/lr.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1046513
URL: http://194.38.20.199/lr.sh
URL Status:Offline
Host: 194.38.20.199
Date added:2021-03-04 10:34:36 UTC
Last online:2021-11-30 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-04 10:36:04 UTC to vb{at}smartmedianetwork[dot]com[dot]ua)
Takedown time:9 months, 1 days, 0 hours, 42 minutes Bad (down since 2021-11-30 11:18:51 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-16n/aunknown 6a38ba834964608961c61c822a16b1ec00285fdcb89998ecc98651e3ebfe131bn/a 
2021-06-09n/aunknown fbff38af9c0b8b11ee493f7413195a337d5cbdd0d1455f55218682f61d141776n/a 
2021-06-08n/aunknown 538d3263ff1e5c478a4f9f55472e02bf40bfe7ff1c2f81954b5ac89210442818n/a 
2021-03-25n/aunknown 407248b231d1b44ea496ce3a2050006e391b96e91ab79a5f63a8c874f54afe82n/a 
2021-03-13n/aunknown 58a1a600af6c2849a48e766a150921c1fa2f8ef209076a66a3736fb87135085fn/a 
2021-03-04n/aunknown 7f82d34906c480afefcd26f969b815794f352a95ce280b4ddb0687ff096c6a8bVirustotal results 33.33%