URLhaus Database

You are currently viewing the URLhaus database entry for http://jbvpshosti.com/1.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3569420
URL: http://jbvpshosti.com/1.sh
URL Status:Offline
Host: jbvpshosti.com
Date added:2025-06-22 19:43:13 UTC
Last online:2025-06-26 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Botnet C&C domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-06-26 02:35:12 UTC to abuse{at}cheapy[dot]host)
Takedown time:7 days, 21 hours, 17 minutes Bad (down since 2025-06-30 17:01:56 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-291.shsh 5861c4bb71a595cbc7d2f8b1b6d964b949859845e1895fd213f5e5d0968688c6Virustotal results 54.84%Mirai
2025-06-251.shsh 8dee740521e955f36594a3a5fc3f5e8f61bc4335698dcb226321719038eca687n/aMirai
2025-06-241.shsh d1f44cc8b17cb6a362e410cae150dbc10c581b4bfb35ee761a3214b71086a4abn/aMirai
2025-06-241.shsh 2e0bd5206319d496d982b1cd36c8e181bc99986156fc529d24e47eb913d6ed18n/aMirai
2025-06-221.shsh 8aad8b019c4cb7ccd20606f9e57b66e7905d0725d64e6b2cb769b176c951d24bVirustotal results 57.38%Mirai