URLhaus Database

You are currently viewing the URLhaus database entry for http://185.204.217.174/z.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1920897
URL: http://185.204.217.174/z.sh
URL Status:Offline
Host: 185.204.217.174
Date added:2021-12-25 20:23:03 UTC
Last online:2022-01-09 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-01-07 13:21:37 UTC to abuse{at}cyberfolks[dot]pl)
Takedown time:15 days, 21 hours, 21 minutes Bad (down since 2022-01-10 17:47:23 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-10n/aunknown 6c724ac30b9e364753f69e6c5f41a8414d7cf787557a79e14d23460ded8d466en/a 
2022-01-09n/aunknown 0127d4984a4993b1485fe3c6036993d2f16d07d7f7e5f1eeea6bf1531271ca1dn/a 
2022-01-07n/aunknown 26da9f164a2581b6d18d6ac9a228f360eed59eae38188b2fae15762866e7e615Virustotal results 36.21% 
2022-01-04n/aunknown 914b2cc0b3fe64a86281b9cd34ad6f3c0efa23d7ed87b867dc69d5fb62e896c0n/a 
2022-01-04n/aunknown 121fe69bd6c1981454ed3a63d6da3991618d93a6143b9f7037e0742010067818n/a 
2022-01-04n/aunknown 457e424a32bfe4481bb50ba74ad251f42aa07b523c37ce9888e7f045408ffa58n/a 
2021-12-27n/aunknown 3013ed2aa05b867bb415d70acd13678ae37268640108bdf174dcbd7dfd64b56fn/a 
2021-12-25n/aunknown 4836da3c1366e1f5cbec1fe5cb07c34b0dbedbd745731d2ef61dc7b5eb0eda0aVirustotal results 53.45%