URLhaus Database

You are currently viewing the URLhaus database entry for http://conn.masjesu.zip/.shell which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3400388
URL: http://conn.masjesu.zip/.shell
URL Status:Offline
Host: conn.masjesu.zip
Date added:2025-01-14 17:22:05 UTC
Last online:2025-05-29 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Malware domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-05-28 18:00:09 UTC to admin{at}serveroffer[dot]lt)
Takedown time:4 months, 24 days, 21 hours, 29 minutes Bad (down since 2025-06-08 14:52:44 UTC)
Tags:sh ua-wget Xorbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-28.shellsh 02d785651e84eb62c6ad7388c01c57a284b4f99144987e2e7be17b6f2a7b75can/aXorbot
2025-05-01.shellsh 9781861f24fb1059ded43d876e310c11948efdc43e7a64655abf76d919a7ebd0Virustotal results 14.75%Xorbot
2025-04-25.shellsh 86e28ad6e7fd509e4c6c16cd7803b10beeddd4c8f25d4218af876b565c43b933Virustotal results 14.75%
2025-04-21.shellsh 8b4c515313d99f78da8e522fd2dee37bd2520bea55568c428c21910a8a4f6c3cn/aXorbot
2025-04-20.shellsh 180e14fce41e89d3b91db291e57cea3763f5281d959bff05b350eb2f6d25fda3n/a
2025-04-14.shellsh c57b1d31e62a2e4bcbbe3c203bc5872541a83ff02e904f90022181a9a00e8895Virustotal results 16.67%Xorbot
2025-03-13n/ash 60ac549d814ada70e9097a69f70f3529a91b90c01c3ee02d2bda770c054c14e7n/aXorbot
2025-03-01n/ash bc74c261d81c630a79c9a793958f1d10a989e05d9e02d0748e994d41bcf26ebfVirustotal results 10.87%Xorbot
2025-02-07n/ash f8131fc6a21d55e9979b7d2c621857e48b63b1062483de9d8507ee169053910en/aXorbot
2025-02-06n/ash f07ae8c69847eab9661713da3388cea50fc9999baf85cafce66431828c694d7dn/aXorbot
2025-01-30n/ash a4bd5a0814626e642d45acc92bc2ccdaeebd359689b23034a0d88df6b6d5be87n/a
2025-01-14n/ash a38e33062c910120fa254c8035d93a0d5b21a5b2e0714cb0e590c0bed1da2294Virustotal results 31.15%XorBot
2025-01-14n/ash ae6d5f558e08966e3c1ed24a693feb1e091fb41f7a5558ec1fedaaf3fb595462Virustotal results 11.48%Xorbot