URLhaus Database

You are currently viewing the URLhaus database entry for http://hailcocks.ru/r.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3289072
URL: http://hailcocks.ru/r.sh
URL Status:Offline
Host: hailcocks.ru
Date added:2024-11-13 15:16:07 UTC
Last online:2024-12-22 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 17:23:11 UTC to abuse{at}fiberway[dot]fr)
Takedown time:1 month, 26 days, 15 hours, 57 minutes Bad (down since 2025-01-09 07:14:11 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-18n/ash a4548e7fc7379c7942cce0e5d9f7c46c6b811da20dc585ad5ecf6974f31ef570n/a
2024-12-17n/ash f8e8bdd8583ad31b0934486b7b5984b2ecb6a3d62f9c5e2b76881c099753667dn/a
2024-12-12n/ash 71dea862bcc45a622aee71b104567a7a95edf51fbbc56284805f8a77f4cfb5a9n/a
2024-12-11n/ash 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738Virustotal results 40.68%
2024-12-08n/ash 304d09035c2a6d68710fe95957548d7f1acd9bfe89423656ae63589f27096edeVirustotal results 52.46%Mirai
2024-12-05n/ash 3ecedaddc9091d81371de52de9ee7842df58dbf7ba6e9c47c9292fec3c190ac5Virustotal results 43.55%
2024-11-22n/ash 1eb8904b245f380c6cd9aebafe43f0f62ec77de2dbb5445325cf24c9a91c4eddVirustotal results 6.67%
2024-11-17n/ash 2d500a063ab29f8b3e2241691f23cd8e9a2a8d40641db3efb2d1ee3d7e3938adn/a 
2024-11-17n/ash f440ab289c213d327da44ede3174226d71fd1e073aa634f50d328f5fb44eb806n/a
2024-11-14n/ash 0b24915811091b00affc2f1fb59d58003fc4440fdb0abe81b7fc4eac90edd27bn/a
2024-11-13n/ash 0669b7eaff043cbb9b3e0e590adc14783c4bd4a9fbb054fb810b1d4d9e13363dVirustotal results 39.68%