URLhaus Database

You are currently viewing the URLhaus database entry for http://59.7.217.245:7070/c.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3728910
URL: http://59.7.217.245:7070/c.sh
URL Status:Offline
Host: 59.7.217.245
Date added:2025-12-07 20:02:09 UTC
Last online:2025-12-24 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-12-07 20:03:16 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:16 days, 22 hours, 13 minutes Bad (down since 2025-12-24 18:16:23 UTC)
Tags:geofenced sh ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-09c.shtxt fb7407f99db4748c8e2362a696b7798234391eb1d8dc34d6a826b81ff0b777d1Virustotal results 16.13% 
2025-12-07c.shtxt 21f6d1a0bf86de1a12596bd776a99a8a610481f5f7b3387d08e2f9d032f2ac4cVirustotal results 12.90%