It looks like you are asking for a blog post based on a specific URL string: http- web.budtv-ultra.com indexs.php .
The attackers are betting that you are curious enough to fix the URL, but too rushed to notice the misspelled file name. Don't take the bet. Delete, block, and move on. http- web.budtv-ultra.com indexs.php
Have you seen a similar suspicious URL pattern lately? Drop a comment below (without the actual link!) to warn the community. It looks like you are asking for a