URLhaus Database

You are currently viewing the URLhaus database entry for http://92.63.197.48/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:101635
URL: http://92.63.197.48/2.exe
URL Status:Offline
Host: 92.63.197.48
Date added:2019-01-05 09:47:05 UTC
Last online:2020-03-12 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-01-05 09:48:03 UTC to hvfopserver{at}protonmail[dot]com)
Takedown time:1 year, 2 month, 12 days, 5 hours, 54 minutes Bad (down since 2020-03-12 15:42:27 UTC)
Tags:CoinMiner exe GandCrab link phorpiex link Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-11n/aexe 0fdd21beb009e9675f955733c80e8053b5dafbb12d22b9cb761af3df82be6505n/a Phorpiex
2020-03-11n/aexe 9d378340ae4e0da80a590927f139f70a875b3809592139024bf27e4c70997f9fn/a 
2020-03-11n/aexe a9e8cc04eb20306734cbb0aaed90746f2e87260a1d66f20413efdf1c331fe0b0Virustotal results 34.25% 
2020-03-10n/aexe e115c62d6bd273a988c07570b40cd9caed1873b8bc85384797debb9182a113fdn/a CoinMiner
2020-03-09n/aexe 468340a7d422c3525d4bb9c274511d77ce715f86f42eb8c790f5cc59bda6c32aVirustotal results 27.40% 
2020-03-06n/aexe 8a3b9a9dc3f14dce7dff9280df58eeb183b4f3b8c57289d05212ce22e25d1c16Virustotal results 20.55% Phorpiex
2020-03-03n/aexe 1565d1de4d537a94e30ccfa2fcd87fcd56245fb03f72ff680ded7c1d1850ff68n/a Phorpiex
2020-03-03n/aexe 2d78656550bb256779b9cadbf5970b5b9b097e600bb6d00bd91775c1eef84609Virustotal results 58.33% Phorpiex
2019-09-11n/aexe b1e0ca203efe0ef4b3302eae10af6a78c9d35cd640f0b397d2b66ebd9982d793Virustotal results 10.94% Phorpiex
2019-08-29n/aexe d12100599ef8bf6d65b49159a00713e7e147d19d387af087e7313fa3a5ef473bVirustotal results 17.91% 
2019-08-28n/aexe eee23a8f3e0b0cb2929057cb468f17297c7b46b1fc5c357e17b56ee6a605121bVirustotal results 62.12% Phorpiex
2019-07-19n/aexe cfa7edc52cb8289ea0822520adf2c116c879c522af81a8aea35e9421a9019535Virustotal results 39.13% 
2019-01-24n/aexe 3fd455b0f5535d825047ad2a8c964e2f9a6d69a02524f8d62e0fc1d8538e769fn/a Ransomware.GandCrab
2019-01-23n/aexe 0fc84d2d657e633f66658c36028e6cf4b6ee9ce474f83b4dc8aad22cd8cfb6b5Virustotal results 25.76% CoinMiner
2019-01-20n/aexe 807d016557f27b3b32e202fd67c7112f293ac5f5cdf6ab3450cc0e485178763en/a Ransomware.GandCrab
2019-01-19n/aexe 36d80c091c3a442fcdbc35c04582ba4843f2774785d173adf8e946163ef01d39Virustotal results 11.27% CoinMiner
2019-01-17n/aexe a1f8f0ab6bfe9b4d893c1c032b6ae2541ea82401aae9077acbe74686446e8b8bVirustotal results 21.43% Ransomware.GandCrab
2019-01-16n/aexe bf9d9de04ed90781080e144c2b0f80e48258fd99ee1ec718b932d802b21faf73n/a Ransomware.GandCrab
2019-01-15n/aexe bf390a0da704a2f74510d09af32ee3bf31f4c7c4c7c38c53e87af1c307fd343eVirustotal results 14.49% Ransomware.GandCrab
2019-01-12n/aexe 0bbe92558569d3b4377d92c02d43cdb8f2c51034a699d9e8a5fb2620f5694814Virustotal results 18.57% 
2019-01-10n/aexe 9a3064a02f7d45b5d073d5653c53694ebfd37af6255a0b928703a11eac4a142dVirustotal results 25.71% 
2019-01-08n/aexe 4b9d5841d38b8658466dcaf409c34c0f6d2d1f9ecb64254391a4621465daf79bn/a 
2019-01-08n/aexe adeca0aff998ca5e0bb3f9f5caa06fc8aea00a024429dcc89e05a5fd63faaaa2Virustotal results 20.00% 
2019-01-08n/aexe f39397b95460f3c04810955b8ab5fb40fcc1c1d96431f1b0d70dde4207f746bcn/a 
2019-01-07n/aexe 334261cfaaedfd30382aa7096fb783ab11d32159cb3e6fc3f7e777c80b858a52Virustotal results 23.19% CoinMiner
2019-01-05n/aexe 134bab5229fef83f9dc6bdc922fe20f906385106282e317dd60302db23a2e5e8Virustotal results 26.39%