URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.37.59/8UsA.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1872448
URL: http://23.94.37.59/8UsA.sh
URL Status:Offline
Host: 23.94.37.59
Date added:2021-12-10 11:01:03 UTC
Last online:2021-12-31 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: Petras_Simeon
Abuse complaint sent (?): Yes (2021-12-16 06:38:46 UTC to abuse{at}colocrossing[dot]com)
Takedown time:14 days, 22 hours, 1 minutes Bad (down since 2021-12-31 04:39:54 UTC)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-30n/aunknown 0478cfd00810c0ec0a7391081fc6c2e3a7593753ff81ccc48d5607ddcedd438an/a 
2021-12-30n/aunknown ca5c19405d1351e304e7bd31c8da338944b76abf9055ec7dd2cc6a67741509cdn/a 
2021-12-27n/aunknown 7872ee440d13d388333e5e7461356fbc01bce61f9e28e4db7e903c1e154df3a6Virustotal results 50.88% 
2021-12-16n/aunknown c1b87dc802b4950dd1ede849f07e03b082d2341aae19579cf643df1d96c33448Virustotal results 51.72%