URLhaus Database

You are currently viewing the URLhaus database entry for http://hailcocks.ru/mass.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3289073
URL: http://hailcocks.ru/mass.sh
URL Status:Offline
Host: hailcocks.ru
Date added:2024-11-13 15:16:07 UTC
Last online:2024-12-22 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-12-17 16:34:10 UTC to abuse{at}fiberway[dot]fr)
Takedown time:1 month, 26 days, 15 hours, 46 minutes Bad (down since 2025-01-09 07:03:14 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-17n/ash f8e8bdd8583ad31b0934486b7b5984b2ecb6a3d62f9c5e2b76881c099753667dn/a
2024-12-11n/ash 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738Virustotal results 40.68%
2024-12-05n/ash 3ecedaddc9091d81371de52de9ee7842df58dbf7ba6e9c47c9292fec3c190ac5n/a
2024-12-05n/ash a340d619066a57f0faa27500a5534273e55c98c9d507c69e513d2b369411be44Virustotal results 40.32%
2024-12-04n/ash b7504ad236b9f5e6d813417131b4ed62093d57e37b48667ec57c4902cdd45b64n/aMirai
2024-12-03n/ash 304d09035c2a6d68710fe95957548d7f1acd9bfe89423656ae63589f27096eden/aMirai
2024-11-22n/ash b32390e3ed03b99419c736b2eb707886b9966f731e629f23e3af63ea7a91a7afVirustotal results 47.54%Mirai
2024-11-17n/ash f440ab289c213d327da44ede3174226d71fd1e073aa634f50d328f5fb44eb806n/a
2024-11-13n/ash 3b0b2a25887920155731cafdc2807a1e4784c62dc6201700a3becaf52ae177ffVirustotal results 50.79%