URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.86.228/bins.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3349080
URL: http://87.121.86.228/bins.sh
URL Status:Offline
Host: 87.121.86.228
Date added:2024-12-14 13:15:08 UTC
Last online:2024-12-16 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-12-14 13:16:16 UTC to abuse{at}nybula[dot]com)
Takedown time:2 days, 4 hours, 49 minutes Poor (down since 2024-12-16 18:05:57 UTC)
Tags:mirai link sh ua-wget Xorbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-16n/ash b57d6888e16f48da6ef0422e150b9972b83ccaf61a66a3c185874c8bf6ebe786n/aXorbot
2024-12-16n/ash a70d61b74ffe91ffc7e649e6d6436fb986bd5bfce32b2914e004741117b6d3cfVirustotal results 26.23%Xorbot
2024-12-16n/ash ce2b41f57f6f47776f1ef005884928a7f9f2b7c7cde93529443767752c27d78cn/aXorbot
2024-12-16n/ash fabbe8eaa4ab13a774916e2854c0ff05c71c85ab1ae58a0c990ee26942ed1a00n/aXorbot
2024-12-16n/ash c010c15a7c2736cd8a2ef68b0d0556a0767b3953acee72a87286a420403a3b93n/aXorbot
2024-12-16n/ash 0cacee18f704a504ed00ebb8ebb9e2b4590e5981ccfc10b7c36e0be2942cf299n/aXorbot
2024-12-15n/ash d9228ec3996200ce1a25e8618318a0a46f3a87a46a0a04653d0d8ce37f85fcd5n/aXorbot
2024-12-15n/ash d3e3af671fc54158a9ce40a3caaa1c6f70268cb8e42246e9d6c28efd7da2cd50n/aXorbot
2024-12-15n/ash 9d48668af17aa243d0fac17fcddcd5487dc53dfe0eb522723e38fa9bf91fb0fen/aXorbot
2024-12-15n/ash 4e83d3fbb19d1463aa811a67614309d1959b249b98d473520fc869abcf693814n/aXorbot
2024-12-15n/ash 38600307f926dc24cb55ab1d9865fe0562f3b0c7b1c4eb458e9b3c16079e1f5an/aXorbot
2024-12-15n/ash 7416f8ae43628688657f5f3b943edd0cbc1bc735d9b21f81e80fe57fe9ca470en/aXorbot
2024-12-14n/ash 1fa505863d5045330db30b33a7668683f28d6481ff899c782c1d9273d56766a2n/aXorbot
2024-12-14n/ash b6f100075fe7b883014f74e0d7f9eb51078bc6b897f0776d9d77a0d22c5c2d62n/aXorbot
2024-12-14n/ash 7231b2146a9e696cfbc6470c95073b8930441b337ed5f597d5e3a6b8a64049cen/aXorbot
2024-12-14n/ash f4eb40a94b334bfad9e738d0fb39bd7c7c1db02ef527ed156982e67fcd1f377fVirustotal results 24.59%Xorbot