URLhaus Database

You are currently viewing the URLhaus database entry for http://92.63.197.60/r.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:16890
URL: http://92.63.197.60/r.exe
URL Status:Offline
Host: 92.63.197.60
Date added:2018-06-08 15:20:05 UTC
Last online:2019-09-03 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: JayTHL
Abuse complaint sent (?): Yes (2018-06-17 06:16:38 UTC to hvfopserver{at}protonmail[dot]com)
Tags:cutwail link IRCbot phorpiex link Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-08-29n/aexe d12100599ef8bf6d65b49159a00713e7e147d19d387af087e7313fa3a5ef473bVirustotal results 17.91% 
2019-08-26n/aexe eee23a8f3e0b0cb2929057cb468f17297c7b46b1fc5c357e17b56ee6a605121bn/a Phorpiex
2019-08-25n/aexe d746e41e18bb637062881aca207186dc3d005e79c857e025f89ce2a1b3e52ecfVirustotal results 38.57% Phorpiex
2019-07-17n/aexe 64d187bed40d023e14d41b1a80d528f5c12dcf743fcb4de91530567d3244e09eVirustotal results 12.86% 
2019-07-09n/aexe 9dbbb31e9df0c42d83a0fa7b610a9438dc3d727d8dd7eaa81418df25f87d5981n/a 
2019-07-07n/aexe 9e38c7f093d4f02631406ca00ed549386e794bf7bc0c53e6147b1cbaf10c8a69n/a 
2019-07-05n/aexe 48393fed57d7c4309373e400080449afa794f665f1a573ab26cfb316de4cef80Virustotal results 30.56% 
2019-07-02n/aexe b1650c6085710bd89fdec14ce9a1a5f52d7199ab98671d994181b1e7116a0a86n/a 
2019-07-01n/aexe 7f9af5447e0da4702f9fefab0bb095b1323813c657c7387e74dcc0774f691349Virustotal results 29.17% 
2018-11-13n/aexe 7afb56dd48565c3c9804f683c80ef47e5333f847f2d3211ec11ed13ad36061e1Virustotal results 1.52% 
2018-08-31n/aexe c73c9e2ba1a42e4183d445696ba84908919e7d1cd6ba3f61e59e4837dc58a35fVirustotal results 42.65% 
2018-08-29n/aexe cdef6a57b2916a39e89c01b9e2798c70a286cc114fe32f27864289fc6db26ba8Virustotal results 44.78% 
2018-07-11n/aexe d739c50e4e0abae20442f9d397129b0ce4563338dc163a6b935b77f4a720ef29n/a 
2018-07-10n/aexe 2c6b23e7ee5c333ab885cc33829ea166eb09b70fae35a685a0e0f08a0622ed01n/a 
2018-07-04n/aexe a771a51473ab688e632ba4e6717f3fc7d687e75fa8fb9a263dca1cbe391631e0Virustotal results 26.98% Cutwail
2018-07-02n/aexe aab61f5aeea9642d2886261ef10893e261383c425c31c29728f5486c518c6befVirustotal results 31.25% IRCbot
2018-06-30n/aexe 570d788a4f7c80274c2d1e00a4bfab2b93ac5ba713b052cab83dac6a8cc62ed5n/a Ransomware.GandCrab
2018-06-28n/aexe c8c3a21f016eee6d35ac8049397bf5e99330188185df53324554c6d3354c768en/a IRCbot
2018-06-27n/aexe 438930af834953d232ded6a0e15b35593b6659431122dd045f02eb4ed661cfa4n/a IRCbot
2018-06-23n/aexe 37aa13626192b5ec81899eb6ac4b6ad5c80666881beb29199d45ea7525d3fce9Virustotal results 30.30% 
2018-06-22n/aexe a34845bc8c0c5e01c6d60201345afb935c65557c99a20a7d4952cc40c3204d4eVirustotal results 22.39% 
2018-06-21n/aexe ad8afd8cb598cee881ab45cadad294fd370ef9ad2a1a806c9e932f2107f5c31dn/a IRCbot
2018-06-17n/aexe 80fe3d31328dec0be3b8fc5142e6caf7538bad4730cd921ba7e3cf2eea2fdbcdVirustotal results 43.94% IRCbot