URLhaus Database

You are currently viewing the URLhaus database entry for http://hailcocks.ru/nsharm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3289053
URL: http://hailcocks.ru/nsharm5
URL Status:Offline
Host: hailcocks.ru
Date added:2024-11-13 14:57:05 UTC
Last online:2024-12-21 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 16:49:16 UTC to abuse{at}fiberway[dot]fr)
Takedown time:1 month, 26 days, 16 hours, 11 minutes Bad (down since 2025-01-09 07:09:19 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-05n/aelf 45a5658d9de647b5f062c9b8839e66ced483772488a19f1375197e2b7bae17ffVirustotal results 24.19%Mirai
2024-12-28n/aelf 16391747c48945e0fde56308fe40f0ef4f0926dbf94862808d91574fdd1892e3Virustotal results 50.00%Mirai
2024-12-21n/aelf 54224f5b5cc2ce6f17833cf449420e27028233380e6d29d23c7ce06692258aa9Virustotal results 33.33%Mirai
2024-12-20n/aelf 61ee479993ea6342e20591591ab68285e33093ea9f6b2a18899c176b6aa4e800n/aMirai
2024-12-03n/aelf 3d528df53f61a76f02dbe7ef8d46559850012e98072bc7f5ee052d1fbd686388n/aMirai
2024-11-13n/aelf 34a9f4f587030b5834bf3194024722c22127e2d98c1f7542587abcffeebe7c7eVirustotal results 21.88%Mirai