URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.66/npp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2517803
URL: http://185.215.113.66/npp.exe
URL Status:Offline
Host: 185.215.113.66
Date added:2023-01-25 05:34:04 UTC
Last online:2025-01-09 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-12-20 07:39:21 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:2 years, 3 months, 14 days, 6 hours, 22 minutes Bad (down since 2025-04-28 11:57:08 UTC)
Tags:32 CoinMiner exe phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-23n/aexe c0d12405d2a5cd6064e6e498d6f5f7fd48c72b2d02f171f20f898a4d2832968cVirustotal results 54.79%Phorphiex
2025-03-19n/aexe 5c09dd7843891805524cf27bea4cf40b4eaa4b0148f511ae2a70417370343cd6Virustotal results 52.78% 
2025-03-08n/aexe fa6fcf2e154c0b18b12ab86267ccd38d79cc9c27e7e261a7e9201a0a9dd9d0bbn/aPhorpiex
2024-11-24n/aexe fc16c0bf09002c93723b8ab13595db5845a50a1b6a133237ac2d148b0bb41700n/a Phorpiex
2024-09-14n/aexe 93237a51bb710bd488b0e5bfa8288751445eafcc795364df7652535f3c210431Virustotal results 54.79% Phorpiex
2024-05-15n/aexe feb4c3ae4566f0acbb9e0f55417b61fefd89dc50a4e684df780813fb01d61278Virustotal results 40.28% Phorpiex
2024-05-06n/aexe ec7dd08d03d5d4142c82fc04cea7e948d05641b0a3008a0d8a00b0421b5b04f9Virustotal results 79.17%Phorpiex
2023-08-16n/aexe 5f28bba8bd23cdb5c8a3fa018727bcf365eaf31c06b7bc8d3f3097a85db037f3n/aCoinMiner
2023-03-11n/aexe d93add71a451ec7c04c99185ae669e59fb866eb38f463e9425044981ed1bcae0Virustotal results 55.07% CoinMiner
2023-03-02n/aexe 66ecd78d60b6b570cc14e088899af8afaad696bc11775c845777aebf7d97234cn/a Phorpiex
2023-03-01n/aexe fc7f4a32ad5d939024f941c04f123edc4e4e51d4974313e001130a2e466119a2Virustotal results 48.57%Phorpiex
2023-02-15n/aexe 9905e86ec9acd294a2ffb88a79b598a8029ee6ff07d794411885ab102bbd647fn/aPhorpiex
2023-02-15n/aexe a1650255f850fabb19b9b75865cef9bd45d89a48390f585f3587da14b7484908n/aPhorpiex
2023-02-06n/aexe 959ed7f57b49523114b54616f2f5bdb40c78cd1fcf8f506d3bc3721e833cee03n/aPhorpiex
2023-02-03n/aexe e9f02e616deb5c63cb19292ae6f9e8f6f6ee950f8172d1a8607256f6a210e978n/a CoinMiner
2023-01-25n/aexe 0c36cf74963333c9fec0b0501043eb38761b76b76946539f374c1c320a7a5dc9Virustotal results 77.46%Phorpiex