URLhaus Database

You are currently viewing the URLhaus database entry for http://109.94.209.121/6.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1578149
URL: http://109.94.209.121/6.php
URL Status:Offline
Host: 109.94.209.121
Date added:2021-08-30 16:16:04 UTC
Last online:2021-08-31 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-30 16:17:02 UTC to tech{at}zbscloud[dot]com)
Takedown time:15 hours, 6 minutes Good (down since 2021-08-31 07:23:35 UTC)
Tags:CoinMiner exe Tofsee link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-31vozbo7ce.exeexe 28fcb32d317739112db767fdf19437cc0626f1189a4b062f02a01ae2be1ad90cn/a CoinMiner
2021-08-31i88drlhhz00.exeexe 74aacdb9c00654e01876d2c1204a4234fc5966fb6aacb0a812820b156f5667c3n/a Tofsee
2021-08-31juptwhnymt8t.exeexe 99f5cbc30c8385cac650c7fe9d72bcb112c86309056650d7fec71dfe4ad0bc87n/a CoinMiner
2021-08-3185fbnywc.exeexe 1f946763403c93b02e89d279eeb5431a5f5dd1105256ef5c67db2f80927b2f0fn/a CoinMiner
2021-08-316tnw3oovo.exeexe cd3fa870e6e87eddf69a7fe57956309d3eb51305a024e7b6a706157356258286n/a CoinMiner
2021-08-31d6rcbdyi.exeexe 2562f965e218faf59ea73899b11589be6d8460e4564164220309b575da7190f2n/a CoinMiner
2021-08-31oxpdcd0ru6.exeexe 158e126d52ce4c041d98d8e9b79721796ccc13022303ab81886ef25c71d5584an/a Tofsee
2021-08-31t12s35a9ydc5.exeexe b375cb25dfad6237a82a130bb1ea436aab1b8dd9c0555fde9b8d75873e7ea069n/a Tofsee
2021-08-301f0s0uoe1qiwzmp.exeexe 491c892f7fda210ca5eb058e62ff68f48772da0dbacf11b2f452ffb36cac8573n/a Tofsee
2021-08-30ti6lw3gtb.exeexe 4b42e7852c7bc8d43541dee196714d06fb60a9b6c71ff85938de1bd564c9990cn/a Tofsee
2021-08-30k6mqbd71.exeexe fbab70493e404f3b67f35362852edcbd674e9a190b508676e196df5a552532fan/a Tofsee
2021-08-30xlvkoimdjx.exeexe 99b99e9723f410cb1d17daf60c6495ecd80e31315ed869cbfb51c561c616589cVirustotal results 33.82% Tofsee
2021-08-30t3wmyd2u.exeexe 8ac1e97f778c574316ab35f7ad7adaf0b11c1bbd7cdaf3031347e5f74f0c262en/a CoinMiner
2021-08-3082ee6kyn.exeexe 2c7053b741f09c2f7185077fe2214c7c6edfc88842c45d6b3203917922a93857n/a Tofsee
2021-08-30i05arzarfrj7.exeexe 425730580e4d21a8cf6fe95c764e42ed219095c8e0fa974c04e8accefee4c13bn/a CoinMiner
2021-08-30e2npb1p4r.exeexe 97e74c877ea7c36d7374a074f562bac15be6e041312f75d99d0603db9515a04fn/a Tofsee
2021-08-302e86ayedju.exeexe c7ad13084ed4a446710393807e8af9056aef30e23ec9891c6aa3c5c45a8cbcc2n/a CoinMiner
2021-08-30n9vwr9wi68at.exeexe f9cd208d6510eb375673db4aa3f35d77f1cbcf3776f97cb1761d65425d7bf70en/aCoinMiner
2021-08-30sqplsjwojqlzlry.exeexe c2c27aff79dec59c7e2cd1dd1a357183df4f9f4dacb7a3425d4c944e413efbccVirustotal results 32.35% Tofsee
2021-08-301ywg8lwd.exeexe a0546540cdeda88593007df77bb650475fce1a88a844b0192cfd6cfaa96b8c83Virustotal results 30.65% Tofsee