URLhaus Database

You are currently viewing the URLhaus database entry for http://103.149.252.178/curl.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3561452
URL: http://103.149.252.178/curl.sh
URL Status:Offline
Host: 103.149.252.178
Date added:2025-06-12 12:10:05 UTC
Last online:2025-07-01 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-12 12:11:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:19 days, 5 hours, 10 minutes Bad (down since 2025-07-01 17:22:01 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-30curl.shsh 03d28e1ea53be7c0dca0bdfb24279824d49136d435ebe519cd4c4d6c8f13699an/aMirai
2025-06-29curl.shsh d0d85fd16b8f40e32fe410bd667b1e9bad0f9f9f5781fd9e7cf421b2ca8b72efn/aMirai
2025-06-27curl.shsh 7a0b3da343e9ce3e38bf933fe21b31bea9d0b2c28c381baf59c655d17c2d33fbn/a
2025-06-24curl.shsh e50e554554633f74465b089271f9a818f53fcd8e66146fb8f556b34cedae7147n/a
2025-06-22curl.shsh 411f61a18b783ea8f33da8c2c30c7ae575e6e8c157ef2c9d103096904ae22349n/a
2025-06-20curl.shsh bb86434907dc86071af8122bb77f81ad1e3ee6934397aa43f77af62a988406b9n/aMirai
2025-06-18curl.shsh d3e4108a9092e282ca4b45c34dc00b84d19205f145f616c9d7014ea9acf0b57an/aMirai
2025-06-16curl.shsh fa2b18cec0e94f9b4465ad67dfa6963fd587f54e4907e89693b7b10769bd1142n/aMirai
2025-06-15curl.shsh 88018f4101d0290fdc8786fb5093a765eb24491312b725a11a3905260e2457d0Virustotal results 20.97%Mirai
2025-06-12curl.shsh 218ff19c50dc1be2e12c9b9a3eff05c8dd8790d774691b38041e95299c13cad4n/aMirai