URLhaus Database

You are currently viewing the URLhaus database entry for http://194.226.139.141/NixwareLoadAdd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1512532
URL: http://194.226.139.141/NixwareLoadAdd.exe
URL Status:Offline
Host: 194.226.139.141
Date added:2021-08-07 01:40:10 UTC
Last online:2021-08-09 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-07 01:41:02 UTC to abuse{at}msk[dot]host)
Takedown time:2 days, 1 hours, 6 minutes Poor (down since 2021-08-09 02:47:54 UTC)
Tags:32 CoinMiner.XMRig exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-08n/aexe 9439f5c9159c444779e9c01bd54499de6bf89452c290135786de3fe26b786358n/a 
2021-08-08n/aexe d410282ce2b3c4db3aebd82851efdb3cbb8d9660e9dce29fd4eb2fcff4a2a7cbn/a 
2021-08-07n/aexe e106f24a8f354f239c8facb587163ad2d5f5a25f201ff1ff46d449cc43e29440n/a 
2021-08-07n/aexe 6a0d05477e23fc1152067fc51d50a044bccf0e0a0654dbae1864df792400e935Virustotal results 42.19%CoinMiner.XMRig