URLhaus Database

You are currently viewing the URLhaus database entry for http://91.209.70.174/Corona.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:212701
URL: http://91.209.70.174/Corona.sh
URL Status:Offline
Host: 91.209.70.174
Date added:2019-06-30 06:18:02 UTC
Last online:2019-12-01 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: MalwareSubmiss1
Abuse complaint sent (?): Yes (2019-06-30 06:20:15 UTC to alexx[dot]person{at}gmail[dot]com)
Takedown time:5 months, 4 days, 11 hours, 38 minutes Bad (down since 2019-12-01 17:59:00 UTC)
Tags:bash qbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-07-08n/aunknown 92108073448a50b8de5ab90dd7923ed624cbbc6bafdf9c35a58576cafb4a3947n/a 
2019-07-05n/aunknown fae1c9a6cafcdf299f86a78ffed4e371b82b05b3f09eb933d866ab3244d0c704n/a 
2019-07-05n/aunknown 9ceb3f5d55b711d670dcc4a0f8801644bdc3e47b224ab06f8498da1b3047875cn/a 
2019-07-01n/aunknown 2588d507b4cb69183f7dc7932411f468bb3feb73cf085b57e871ea0c18526447n/a 
2019-06-30n/aunknown ddcbbdc36f1e7d21ac5c500ad3d577c126ca4d4f1f789f087a81d702992bb950Virustotal results 33.33%