URLhaus Database

You are currently viewing the URLhaus database entry for http://78.142.229.12/logsbins.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3576542
URL: http://78.142.229.12/logsbins.sh
URL Status:Offline
Host: 78.142.229.12
Date added:2025-07-05 09:49:08 UTC
Last online:2025-11-03 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: xqtsmvjnxuurv
Abuse complaint sent (?): Yes (2025-07-05 09:50:13 UTC to report-abuse+xtom{at}virmach[dot]com)
Takedown time:4 months, 1 days, 9 hours, 0 minutes Bad (down since 2025-11-03 18:50:35 UTC)
Tags:gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-07logsbins.shsh 9d58c8da57d83083136f5bf2ca519d11bc3a503d643835fc515920958993cd9cn/aGafgyt
2025-10-05logsbins.shsh 598869183031b582180968c6db4e8f01fc00be2f8a56f9ddae1fcec3d561305an/aGafgyt
2025-08-26logsbins.shsh 0cbca43f0b524cd4e31efb11889c4282ef3458b94e5645aacea68e0bba285688n/aGafgyt
2025-08-14logsbins.shsh 33f9531a11c288d569ac5d47a256b57c6d8d07a9e6b1ce8cb37bed6ac8a1cfe6n/aGafgyt
2025-07-24logsbins.shsh 3cc01356c5430ef2eee49ae35103f1e0288488cded861acd22356123241153e7n/aGafgyt
2025-07-11logsbins.shsh 4eb31fecafcac29addc2040a2e89174fd9f44b34444ebe05e14b5590722d5502n/aGafgyt
2025-07-05logsbins.shsh 01f70d01692a9bae3b94730ba359804c9c14d90c749a0773072d8cc356115aa1n/aGafgyt