URLhaus Database

You are currently viewing the URLhaus database entry for http://squadlegion.kozow.com/b.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1646841
URL: http://squadlegion.kozow.com/b.exe
URL Status:Offline
Host: squadlegion.kozow.com
Date added:2021-09-28 15:12:07 UTC
Last online:2021-10-08 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-08 17:45:06 UTC to audit{at}firstbyte[dot]ru)
Takedown time:1 month, 14 days, 22 hours, 41 minutes Bad (down since 2021-11-12 13:54:32 UTC)
Tags:32 CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-30n/aexe ec4b67a2beae184593b02b64434241983edc805fda2e43701115efb1ccb4c28dn/a 
2021-10-30n/aexe 18dc00c42cfda5913af32f1fdb0208b436f2e1d4629485d6cf54e85fb51f79cen/a CoinMiner
2021-10-30n/aexe e6833b82c7f442e159857c198ac59d3ec2161a675a6d091f16b5390df4946cddn/a CoinMiner
2021-10-30n/aexe c6a24a2c6bf1bb9b804ffb4e3e4c8359d06f7520f573e329ee1d425a186a74d5n/a CoinMiner
2021-10-30n/aexe a47e7ba3903cd77c5d15bbb6841dcb196783c0c753a690ac19366b02f0bdd94dn/a CoinMiner
2021-10-30n/aexe 38a3086bea0968dcbf4a52cec904bcfc93ae3c7ab10a5e6db19aad622665aed9n/a 
2021-10-30n/aexe 91898baafcfcbde9fbea557b433be1d410405a1e60520e14552fa1f37dd5a26bn/a 
2021-10-30n/aexe 6ff3be0f8bf943e7fc84ef40a4623427b8887c281afdd74622d45b3c6ce649ccn/a 
2021-10-30n/aexe 6e2b13accb0943ec78fe79300615756b2db2fd3f3b984cc5c04ac35ab7cc5128n/a 
2021-10-04n/aexe bc529d223dd926485efd3cae4bda9c24fe228c4e4bde28329b2e4cb36509a694n/a 
2021-10-04n/aexe cf6953f285c658694718279fadef8228f724586a4d8cafa1c81f42af476bb6e1n/a 
2021-09-28n/aexe 715e1eb5414e749e16fb3999dda7bcf8405e6fb4e14e66ddcbdf20a2e1af89c3Virustotal results 65.22%CoinMiner