URLhaus Database

You are currently viewing the URLhaus database entry for http://hailcocks.ru/nsharm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3289058
URL: http://hailcocks.ru/nsharm
URL Status:Offline
Host: hailcocks.ru
Date added:2024-11-13 14:58:05 UTC
Last online:2024-12-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 15:40:17 UTC to abuse{at}fiberway[dot]fr)
Takedown time:1 month, 26 days, 15 hours, 55 minutes Bad (down since 2025-01-09 06:54:08 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-05n/aelf 2f764a8c1c9131f763a1951f7ac5d3c95731dc13ee8d7b14823a53a9f34662d3Virustotal results 20.63%Mirai
2024-12-28n/aelf daada5e94b6f69ad4e05132e8f214e389903db52e41b3d429ec2f7b1e5e9a240Virustotal results 47.62%Mirai
2024-12-21n/aelf 218e5746aba8cec848c85401115db0ed0b30245084935813efc756434389c4c0Virustotal results 32.26%Mirai
2024-12-20n/aelf 536e51ec95627d4b8dc490b09f9040ea631ec39036c54c38011cd54cd30728f2Virustotal results 31.75%Mirai
2024-12-03n/aelf 00cad597298a9b243fdb3828c5251d7e90df5a033a9d263727ea2a1b07ea565en/aMirai
2024-11-13n/aelf 1752a1eff046cdaa72b269218512ff202712e43b3b253362d5ef945134b44cfeVirustotal results 21.88%Mirai