URLhaus Database

You are currently viewing the URLhaus database entry for http://193.143.1.66/hidden.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3402722
URL: http://193.143.1.66/hidden.sh
URL Status:Offline
Host: 193.143.1.66
Date added:2025-01-16 15:24:05 UTC
Last online:2025-02-01 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2025-01-16 15:25:18 UTC to abuse{at}proton66[dot]ru)
Takedown time:15 days, 10 hours, 56 minutes Bad (down since 2025-02-01 02:22:05 UTC)
Tags:mirai link script

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-27n/ash 5c24259723cfd073bce776005d904f5894da9fb8ec2398e0f47b0a77115c6812n/aMirai
2025-01-25n/ash 7308d85aa1acfcb9800f78200674f8b5497d3838d5170ac5e3717118f1634984n/aMirai
2025-01-24n/ash b954ed9586e5b2dd4df43660be9ea32609769edea0ea22886c133706cbb65224n/aMirai
2025-01-23n/ash 309845ebfc33395d1a03acd19510bbdccfb6543df0a4b1a95e26395cbe1ae4b9n/a
2025-01-20n/ash c65d5cd617018be7dae188bdc301bbd537f5bac8b4c8cb81a564f197fd2050aan/aMirai
2025-01-19n/ash b6441119603c0adc33902485fdd6d3cbfd9eae6d6d85642466044c3d7ff9e181n/aMirai
2025-01-18n/ash 8930aa2fce8f7c07dfbd99d5fe061ee4519956d2b2cec2d9a7f05668b3ad3e42n/a
2025-01-18n/ash 9b2c44a0a185a4a7bb7c88341f39cfce9c6f6fe1ab9cd555ed0c6591264e6b9fn/a
2025-01-17n/ash 41d571de02b6b96f4e360f9b9c42798054a1faa8a95cc75acbf6ff3aed01bc08n/aMirai
2025-01-16n/ash 6a21d9dad02f7d0f812415718b382417ee5214ebefd2af8e8119e2f5c34d10ccn/aMirai