URLhaus Database

You are currently viewing the URLhaus database entry for http://101.33.238.116/wget.sh?run_ddos which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2044450
URL: http://101.33.238.116/wget.sh?run_ddos
URL Status:Offline
Host: 101.33.238.116
Date added:2022-02-15 16:36:04 UTC
Last online:2022-06-11 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2022-05-13 04:54:06 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:29 days, 6 hours, 14 minutes Bad (down since 2022-06-11 11:09:02 UTC)
Tags:shellscript

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-11wget.shunknown cce6cf4ec56ea9960281f21981ec76abf6da85b2f23e9abf46ab77f966fc259fn/a 
2022-06-02wget.shunknown ff1547b51701e260fe76b5305c013deaa97ecfd11322dce77bbc06f61082f7d0n/a 
2022-05-27wget.shunknown 865dd25fa100b8b3a0a2d27deca9c0e3c83a9fec55780da430cfba99676bea84n/a 
2022-05-24wget.shunknown 62a310c65885ca24ce133dec7295c76361b43a7efb9ac8ddfa19a9bad4d5e09dn/a 
2022-05-24wget.shunknown 527e90695f6c6cb49824a639a9cbffc08599f076c84536a0b961a69923ea2a7cn/a 
2022-05-13wget.shunknown 896c5dc3fb5c215bc3e8966a481190d7d1167d1668e32425c4226555fd1490e4n/a 
2022-02-15wget.shunknown 56162b255de9aaec5fe2cb7acb06b02b95a488855cf7dfb3e99d9ccd5c6d0adbVirustotal results 22.03% 
2022-02-15wget.shunknown f691de2f7199327a6616d4c99bb5c7ef464dcc95394f77812314d38fe8f7be5fVirustotal results 39.29%