URLhaus Database

You are currently viewing the URLhaus database entry for http://top1miku.duckdns.org/1.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3592535
URL: http://top1miku.duckdns.org/1.sh
URL Status:Offline
Host: top1miku.duckdns.org
Date added:2025-07-29 06:47:11 UTC
Last online:2025-08-17 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-11 17:14:09 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 13 days, 13 hours, 42 minutes Bad (down since 2025-09-10 20:30:46 UTC)
Tags:botnetdomain gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-121.shsh a3a9a2e726af19ac268d6c9a42680e495217985724ed52b01ada3d704a63f8d3n/aMirai
2025-08-111.shsh 4efde3869fbaa379965052f638afbe90ec25ce4e8ee9f315f23e945d1e0ac969n/aMirai
2025-08-111.shsh e4d3b32d83897c27b4c24a28fa0c477c23b1b0cda57eeeabf039628aebb3cb71n/a
2025-08-031.shsh be3c7e8b92bea27a8441d8e04058626a059a59659039422dccc6c99e16669599Virustotal results 37.74%Mirai
2025-08-021.shsh 31634c4474561da7783a19b9146ac8a2c851562bb06f2a37047114f81518c898Virustotal results 54.10%Gafgyt
2025-07-311.shsh 9623e018ac42834b0b3d73c49426cb6a5bf3ac84eee38d433061e0ce3a03847bn/aGafgyt
2025-07-291.shsh 555ba720db0587411c1b0417da105b95af9cb1d1bcfad0b819418b2e8ea81bd8Virustotal results 50.00%Mirai