URLhaus Database

You are currently viewing the URLhaus database entry for http://95.143.178.121/javXhgUA.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2044439
URL: http://95.143.178.121/javXhgUA.exe
URL Status:Offline
Host: 95.143.178.121
Date added:2022-02-15 16:22:03 UTC
Last online:2022-04-04 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-02-17 17:06:40 UTC to abuse{at}selectel[dot]ru)
Takedown time:1 month, 16 days, 3 hours, 5 minutes Bad (down since 2022-04-04 20:12:36 UTC)
Tags:32 exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-28n/aexe e36b2fe70c40908fbd6bd5b3165eeb60f4b98a5cc90e25e0dd382be9900cdb6bn/a
2022-02-23n/aexe aa69efc6d0e9dcf29dbf1894cadd436c295bc1ed05684fbf8731a9cb0e8d183en/a
2022-02-16n/aexe 7d8d7b392931969c02d39f5c2f55e47611ffea9f556bbcb306ef562b644ac3b4n/a
2022-02-15n/aexe 72432ed9dc08002f4e1d8868c872dbba775c744b5eb6f6a17b41e584daae8a2fVirustotal results 47.83%