URLhaus Database

You are currently viewing the URLhaus database entry for http://scanbot.me/shell/rev.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3878283
URL: http://scanbot.me/shell/rev.sh
URL Status:flame Online (spreading malware for 1 month, 28 days, 17 hours, 35 minutes)
Host: scanbot.me
Date added:2026-06-30 00:53:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-08-20 08:01:18 UTC to abuse{at}cloudflare[dot]com)
Tags:ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-25rev.shsh 86ed56a768baf73b0785a9a3a2bbd5213b47848503904ea43dffd9b6dfb4cbd3n/a
2026-08-19rev.shsh 4586895f0d7e2491fc1a5c923f9b039139eb5459cd6b449c8345ab07c675e5b4n/a
2026-08-13rev.shsh 1752db4051fb047a2fc8eb9ae4bb1aaa7636acf67bf26e67b34e71f6ced08ac9n/a
2026-08-08rev.shsh b98f565f960397b76fc2a93f82f8479dc24991cd24c5b7d41b74ec6c81f11cafn/a
2026-08-04rev.shsh 880c13a1834befc989afd2da1a8ceb4cd5f533a9b614f1ca7e832f14167dcdccn/a
2026-07-13rev.shsh 52f39d0c0d008faf84dbd944cd37d20db616ffe1b2202222129d94951074625an/a
2026-07-07rev.shsh 4e879681faad8b843924405353350f5e71908b68cc8155e9d6a953b0fc099f2cn/a
2026-07-03rev.shsh 22302cf76c98f4f9162d39018746c9616ac176138889f3cabaa952807148c7dbn/a
2026-06-30rev.shsh 072b708c1658e2744b77af796f5f12b9edd0bcfed6aa338fafab2891de868205n/a