URLhaus Database

You are currently viewing the URLhaus database entry for http://5.133.65.53/Oracle/$77_loader.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1925806
URL: http://5.133.65.53/Oracle/$77_loader.exe
URL Status:Offline
Host: 5.133.65.53
Date added:2021-12-27 19:56:05 UTC
Last online:2024-05-07 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-27 19:59:43 UTC to abuse{at}balt[dot]net)
Takedown time:2 years, 4 months, 21 days, 15 hours, 39 minutes Bad (down since 2024-05-07 11:38:53 UTC)
Tags:CoinMiner CoinMiner.XMRig exe RemoteManipulator link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-17n/aexe 4684200439a26f7da4570c7ecaa16679712b1aa9d6c52bae31360ac33fd6606cn/a 
2024-03-16n/aexe a04e1981b25bf7dd9d4cf8f3071f59446e199343a7f08dbbf2f093f65eb74301n/a 
2024-03-16n/aexe 8c84f20b58814beadd3962a63853e98f0e2b6ea33bd893d1e0249b2ca49eef6bn/a 
2024-03-16n/aexe 3d0b1ea9067a029f28e2f4490dd03404a9cb8c87268c63f0672be3ea0259be5an/a 
2024-03-14n/aexe c67ac101ecf6b842e60c8fc72e81657cc41c05b434a93ed541af28b9818f4d62n/a 
2022-12-28n/aexe e24ca5bcd8745a9ea01fcab410eb03e2151d6792468535095dcadfcd59ec60f0n/a
2022-12-13n/aexe 573a69dd07afe720d2824999ac3d03766d584e029ae0afc2020ea531996f7f5cn/a
2022-12-12n/aexe 4773b0f5d97c02b9db3eae415f86ffe4cd3f7e83e12bf30fb5c7b25190a4b705n/a
2022-05-24n/aexe a3357e7ea44e4d30304b1e5a4f53da37c848ce10fda0bd03a4f0dc0c5220e336n/aCoinMiner
2022-05-18n/aexe 4547b578ed4468731e348a47a16a26beeaf192c616b70d575f3a04328978a981n/aCoinMiner.XMRig
2022-05-18n/aexe b371b51337e99fcc788bdf4a22f3181a6feebbd663570e5ecebab4778dd46fc6n/a 
2022-05-18n/aexe 0a7e84e07d7dffea2925e5a508c2a419ffd2a44f110e0645972e4d077d8822b4n/a CoinMiner.XMRig
2021-12-27n/aexe 3826953ded758361f9783d67242e4ba87092d637d72bcf81c649e52665c57de4Virustotal results 13.43%RemoteManipulator