URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.241.136/files/file1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1288301
URL: http://212.192.241.136/files/file1.exe
URL Status:Offline
Host: 212.192.241.136
Date added:2021-05-26 21:07:02 UTC
Last online:2021-06-26 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-05-26 21:08:02 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 1 days, 1 hours, 59 minutes Bad (down since 2021-06-26 23:07:37 UTC)
Tags:CoinMiner exe gcleaner link RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-07n/aexe 255a309aa4ac9d53e3de0f3247b3388d6376af9efb19f8256fd8d1db5bfb2448n/aRaccoonStealer
2021-06-06n/aexe 1eb4b2a30f7d2822fc91b6ead0a0524d381a17cf0cba9603fa3779aff8894e6dn/aRaccoonStealer
2021-05-28n/aexe a7f1abd61dcf67897083df90942e88a43570b4d60eef1c63e440aafeb3c67448n/a 
2021-05-27n/aexe 48546069c858ac5033f7c25c170fd3a0da1573b715849579c33ad9df21a824dbn/a GCleaner
2021-05-27n/aexe c70a67a13b5977d741ed50e16b2a6817b8280cd28254ad01a562e0c114757652n/a
2021-05-27n/aexe c194fc8cfaccff275896f4a8d60b07156aa9f3180620c0c003daacbadefe9371Virustotal results 42.86%CoinMiner
2021-05-27n/aexe 081d46c9eae290ad95937c1e87ac2fbae0b345ca7d00a4fe7d5ed8384d200ac7n/a
2021-05-26n/aexe 533ae8a3da85287304c89e2758f9bd5e54c586b2c13a152e34033d1884eb7d16Virustotal results 33.33%RaccoonStealer