URLhaus Database

You are currently viewing the URLhaus database entry for http://185.106.94.146/deliver.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2517959
URL: http://185.106.94.146/deliver.exe
URL Status:Offline
Host: 185.106.94.146
Date added:2023-01-25 09:28:05 UTC
Last online:2023-03-07 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-01-25 09:29:05 UTC to abuse{at}aeza[dot]net)
Takedown time:1 month, 11 days, 7 hours, 37 minutes Bad (down since 2023-03-07 17:06:27 UTC)
Tags:AsyncRAT link CoinMiner CoinMiner.XMRig exe PureCrypter zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-11n/aexe f4d9fd83682ed1579836cd93c23c26857253a1cea223fe1050be42f3eefd883an/a zgRAT
2023-02-07n/aexe cd9adc5d92164b006e82ebc2498f7b1cd47656e3d2f1bdfd78351311224c5f66Virustotal results 32.86%CoinMiner
2023-02-03n/aexe 14d6746a7475a0f8cd26d1d30403688e8d36cdc3f093e159f5882dc614a0cccbn/a 
2023-02-03n/aexe 8569779fd0dcb07af7d0af2f6c93af6cc29158161a1f55af904677faa00cc6cdVirustotal results 23.19% 
2023-01-31n/aexe 1501ed409db46bc33f3f4a13c9d2150308597fb91cff20e04c9df0d5f3dec37dn/aPureCrypter
2023-01-31n/aexe 6ad71236a8807687b670fe635f799ad2f811d88e9f7d8075d3df4cafeb1cbd45n/a CoinMiner.XMRig
2023-01-30n/aexe 0b6b761cc209ec7b5b237de741bdcc878a3691b22bcb24ea9246d940e72de7fan/a CoinMiner
2023-01-30n/aexe cfc9e35e650fccb171caa30fd7db3f6b99a8a16e824fb3f6276526ff10e063cfn/aCoinMiner
2023-01-28n/aexe f0a3884252d20ae26d34a40eb5cf36d9a23e67b97483b6d629ed2af9c14bc15cn/a CoinMiner.XMRig
2023-01-25n/aexe ca4033db02bded2739ca4e31c72910e4c5995f9437cda0c4767a8113166d84b6Virustotal results 19.72%AsyncRAT