URLhaus Database

You are currently viewing the URLhaus database entry for http://103.149.252.178/busybox.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3562359
URL: http://103.149.252.178/busybox.sh
URL Status:Offline
Host: 103.149.252.178
Date added:2025-06-15 21:52:07 UTC
Last online:2025-07-01 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-15 21:53:10 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:15 days, 18 hours, 23 minutes Bad (down since 2025-07-01 16:16:58 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-30busybox.shsh cb894059764a25d53785b0745191805a775872b11ce1a5ee24b9d5688c26a969n/aMirai
2025-06-29busybox.shsh a04b02542313de5db70d5a87fcaf23a5c7d1cd58d9b931b5e6f7045f134708c8n/aMirai
2025-06-27busybox.shsh 2578216acbad758fde4efd8d8d04d3fef0bf41845532851cc9cec37a48421d55n/a
2025-06-25busybox.shsh 5299c29bd235bb02782d58f5747227a114a68359a686e0e358a3ea47622c66e4n/a
2025-06-24busybox.shsh 2670466de85480cbf02219e7ffadb5b176c6ea74ae2e2b3b95a98e4590c8a98aVirustotal results 16.39%
2025-06-20busybox.shsh c2a3fa80b8f472410b5ae5e36c8b9b451de01eeed131f28182241ab3d07197f9n/aMirai
2025-06-18busybox.shsh c90adf8f183f1ef3cc0b8aaa8f6efdf8833ac5888ebc2bc708d029c5f1a7cf27n/aMirai
2025-06-18busybox.shsh 4cc486a1eda883f3cb4aba85cac02f8049f27285d043d5181327c498c5d33946n/aMirai
2025-06-15busybox.shsh 45b5e91f8a85f5ff1bdd5281f2ebc93d338f6dc82356000af4c5bbc20e1733acVirustotal results 22.58%Mirai