URLhaus Database

You are currently viewing the URLhaus database entry for http://hihi.trumdvfb.com/wget.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3561034
URL: http://hihi.trumdvfb.com/wget.sh
URL Status:Offline
Host: hihi.trumdvfb.com
Date added:2025-06-11 20:22:07 UTC
Last online:2025-06-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-15 16:49:10 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 days, 3 hours, 0 minutes Bad (down since 2025-06-21 23:23:13 UTC)
Tags:botnetdomain censys mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-21wget.shsh 7f3b5f8d7eb6fba8a1a9ff8c8177f20adff2dab75cca40bf38161f6afd82ef9cn/a
2025-06-20wget.shsh c689f30df176e7ce997b7f0a3c7bd6e0c6fb86bf1a71e0c35ab91cbe634be517Virustotal results 30.65%Mirai
2025-06-18wget.shsh 0b768ac1a55b164a39dc9af29102016a5417b6c038b427683641333881b3867bVirustotal results 25.81%Mirai
2025-06-18wget.shsh 0d1414266f81e3c38a0b0d5dafae47ea8ce86d484ec5bbf345aebee75c9bace5n/aMirai
2025-06-15wget.shsh 12920f5a6ce8579b3ca0b0d9ee37cfffbcab028a6e875418d4d0c34072c4f6d0n/aMirai
2025-06-11wget.shsh de453a8a183ba3b9a88f648eca2b0cee1f4eb21f0cbcf0f73ac4e416285cf216n/aMirai