URLhaus Database

You are currently viewing the URLhaus database entry for http://80.71.158.96/nazi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1989170
URL: http://80.71.158.96/nazi.exe
URL Status:Offline
Host: 80.71.158.96
Date added:2022-01-19 10:49:05 UTC
Last online:2022-04-17 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-01-19 10:50:11 UTC to abuse{at}ntup[dot]net)
Takedown time:2 months, 28 days, 6 hours, 48 minutes Bad (down since 2022-04-17 17:38:16 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-09n/aexe 83fba7250babf63e8730b96c4ac1171df295c19aa66acee77850cd1e6ffbb0d8n/a
2022-03-01n/aexe 7077c78e6fba842bde4a7b91704864b881f1e0eb49d81b07c758a5917860170bn/a 
2022-02-28n/aexe 4802e455c56a01a9f8ad1fb7291c468503dfb399e7e54d304a00e4f6db030d45n/a 
2022-01-19n/aexe d71902d94f791bc465df2e02f65b2c45f1abce409d173a040df1dcdb64e5d2f7Virustotal results 42.65%CoinMiner