URLhaus Database

You are currently viewing the URLhaus database entry for http://banthis.su/wget.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3352168
URL: http://banthis.su/wget.sh
URL Status:Offline
Host: banthis.su
Date added:2024-12-16 14:20:10 UTC
Last online:2025-03-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-01 17:35:08 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:2 months, 15 days, 7 hours, 20 minutes Bad (down since 2025-03-01 21:42:06 UTC)
Tags:404 botnetdomain mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-01n/ash da80863061dc0e02682bb76dcb69b6012e205d7c55252ec228416cdc813bc81en/aMirai
2025-02-28n/ash 6918e5351924a5df8a94a50afc2e634977d30cbd1c7c0123e3bb72c85d11fab6n/aMirai
2025-02-16n/ash 47f2b64af6b8bb6d7db40ae5febeff478515043ffce1bd304c258683f9d9282cVirustotal results 7.32%Mirai
2024-12-16n/ash b6a6cd4a15be361c9154510b635330d6f73c25fe022e5a4518af5a4518610c15Virustotal results 30.51%