URLhaus Database

You are currently viewing the URLhaus database entry for http://176.31.32.199/Stub.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1644587
URL: http://176.31.32.199/Stub.exe
URL Status:Offline
Host: 176.31.32.199
Date added:2021-09-26 15:36:04 UTC
Last online:2021-10-07 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-26 15:37:03 UTC to abuse{at}ovh[dot]net)
Takedown time:10 days, 23 hours, 59 minutes Bad (down since 2021-10-07 15:36:26 UTC)
Tags:32 CoinMiner exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-06n/aexe 23f725498a107dd110eccfa4c8728fbeb6073b7c207a4509f19057082d82e6f3n/a
2021-10-05n/aexe 836552a532086665828a890a5e47b45ea98b9f638a4dac0ac0ba09d3c34f8c86n/a
2021-10-05n/aexe eea8eafcc49becb8d96e50f297abdb3f9fc4ddc1f0c7a44c278ef22c852812fen/a 
2021-10-05n/aexe 76b53b926cddeecc9b3eb9c17dc7ab0cdbed07eba2a75beb3f4342d0bfa65158n/a 
2021-10-02n/aexe 7c3f390f58bd6635171375748cbbba82ccb9502687004595799cd497c3fc8615n/a CoinMiner
2021-10-01n/aexe 040e76d98de6f2faeefdfff6e5c1c2b892a246cc028fa90cb67291714d91086en/a
2021-10-01n/aexe eb41f0d7fa86d49349be3d44f29f71bb3b93091f2894eae69371e0d12310f6b9n/aFormbook
2021-09-26n/aexe ba319ab5c744553d08d3e981e76445631626be828e08bfa84487ae19434912b9Virustotal results 60.87%CoinMiner