URLhaus Database

You are currently viewing the URLhaus database entry for http://45.144.225.135/msiexec.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1423538
URL: http://45.144.225.135/msiexec.exe
URL Status:Offline
Host: 45.144.225.135
Date added:2021-07-03 18:17:04 UTC
Last online:2021-07-25 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-03 18:18:03 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 5 hours, 1 minutes Bad (down since 2021-07-25 23:19:19 UTC)
Tags:32 CoinMiner CoinMiner.XMRig exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-21n/aexe af18c1e923667ab287cd2699203e0bb6e6030dee131299ea670bc842dec76745n/aCoinMiner.XMRig
2021-07-18n/aexe 81a171b0960d845b4a5c0e5973d63860e8ba0575fa9d96f2b91db9c80e98d624n/a CoinMiner
2021-07-16n/aexe baaad3ebe858dfe15566fa8092f311e73bf2669c2e2e0aecf405d638371392acn/a RedLineStealer
2021-07-13n/aexe 2aaa01331614da8dbf03d0fa4ab8113ae2d01fa79732ef7dac33eafe9f9c9694n/a CoinMiner
2021-07-13n/aexe 5802131b2238371d1447e39b931f7703a83023aa8c7f68632d5425ab25968f1cn/a CoinMiner
2021-07-13n/aexe d85517fec7ac1a9a77a885b63ac5c1503e72da0741a587953a37c786c9fabafan/a CoinMiner
2021-07-12n/aexe 57736c82b0f960c2718946166b717eff1e5a964d271d81018450cfc3d6f48fa7Virustotal results 34.29% CoinMiner
2021-07-10n/aexe 0359962e8868dad773372f8bc9d733e04811718e512c0f83575a9111ddf863f1Virustotal results 33.82% CoinMiner.XMRig
2021-07-08n/aexe b5dc6df4e9d916141e14548f08f18e202396fe7c952a885456228253dbf6696fn/a CoinMiner
2021-07-05n/aexe 081e8ed53dbbae2aca6b01f23c881f03890baa82a0c82929dc2977112c0fab1cn/a CoinMiner
2021-07-03n/aexe c4a2ff17b64e24fbf00d70d2d4b996332cb7a4767f2c27e6a2ff93999cc44e67Virustotal results 30.43%CoinMiner