URLhaus Database

You are currently viewing the URLhaus database entry for http://hailcocks.ru/wget.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3192469
URL: http://hailcocks.ru/wget.sh
URL Status:Offline
Host: hailcocks.ru
Date added:2024-09-26 11:37:08 UTC
Last online:2024-12-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-17 19:39:11 UTC to abuse{at}fiberway[dot]fr)
Takedown time:3 months, 15 days, 0 hours, 24 minutes Bad (down since 2025-01-09 12:02:51 UTC)
Tags:botnetdomain elf HailBot HailCock HailCockBotnet mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-21n/ash 52a7dc89ce2758ae2577d7be189572e66fe528a78b7bf2577ec1eed7935364e9Virustotal results 31.15%
2024-12-17n/ash f8e8bdd8583ad31b0934486b7b5984b2ecb6a3d62f9c5e2b76881c099753667dn/a
2024-12-11n/ash 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738n/a
2024-12-08n/ash 304d09035c2a6d68710fe95957548d7f1acd9bfe89423656ae63589f27096edeVirustotal results 52.46%Mirai
2024-12-05n/ash 3ecedaddc9091d81371de52de9ee7842df58dbf7ba6e9c47c9292fec3c190ac5n/a
2024-12-05n/ash a340d619066a57f0faa27500a5534273e55c98c9d507c69e513d2b369411be44n/a
2024-12-04n/ash b7504ad236b9f5e6d813417131b4ed62093d57e37b48667ec57c4902cdd45b64n/aMirai
2024-11-22n/ash b32390e3ed03b99419c736b2eb707886b9966f731e629f23e3af63ea7a91a7afVirustotal results 48.39%Mirai
2024-11-17n/ash f440ab289c213d327da44ede3174226d71fd1e073aa634f50d328f5fb44eb806n/a
2024-11-08n/ash 3b0b2a25887920155731cafdc2807a1e4784c62dc6201700a3becaf52ae177ffVirustotal results 45.16%
2024-11-01n/ash fbe8234329cfc678ca2b51f78b3c6f7886d658b74274bc97c06bffa20cd6b2c7Virustotal results 41.94%
2024-10-31n/ash 0b4536fb2b282d634be632691690bb99eede7cd0306b9409c982d1880d418aeeVirustotal results 43.55%
2024-10-27n/ash 1c14a5edb665773c858b43818b84ea952e00dfb15080995fcf1d38fca4da4213Virustotal results 49.18%
2024-10-01n/ash d71d0a7942fd04ee4139f1eeda6ec72a169abe55f1df5c02afa174b4965b98f1n/a 
2024-09-30n/ash 94d1a6773595bd631d315b307891064a1bc3b70e7d77f4ce49b470945d111592n/a 
2024-09-29n/ash c6c758128b21a177698bfd3eb46f06c7d6e6db28e080c42500887426e74eac54n/a 
2024-09-27n/ash 5981a182e970835f7a25bc0ec4d36fcd97028e427bc07f2110c6cc7350723004Virustotal results 48.33% 
2024-09-26n/ash d9c7cc12c71212d806a0927b9c55567d405ba070922337e60d80a9242839140fn/a