URLhaus Database

You are currently viewing the URLhaus database entry for http://217.196.96.130/conhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695245
URL: http://217.196.96.130/conhost.exe
URL Status:Offline
Host: 217.196.96.130
Date added:2023-08-01 20:26:05 UTC
Last online:2023-09-16 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-08-01 20:27:05 UTC to awore[dot]ru{at}gmail[dot]com)
Takedown time:1 month, 15 days, 15 hours, 29 minutes Bad (down since 2023-09-16 11:57:04 UTC)
Tags:32 CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-06n/aexe ae68aa627df4a3fd10e5416195e29203ea60227560f3e1de22fb907e86c369adVirustotal results 18.57%CoinMiner
2023-09-01n/aexe c379e979e5870cc97c117abf85613cc9b1b719fc40d12a6a746effca70a8dd54n/a 
2023-08-24n/aexe cff4738febe9bfbeeaecf20bf24ec7acd19ed5b94f364da02d09bdedcbf50f91n/aCoinMiner
2023-08-21n/aexe a1c121a2367d28d2fe8e9b448913cfaa01c86fe4a872061680f0706069e8c1a6n/a 
2023-08-10n/aexe 502bad2e589fe3994104ee8c841d403cb706bf755f4ffad1eec45062acde54b1n/a 
2023-08-08n/aexe c60ecd5714a23a727d9749652883ec95bcdb350b9f278c34ac504edb898073e4Virustotal results 67.65%CoinMiner
2023-08-01n/aexe 38e66e1c80433f2a4e16a708f8cb5e26ed32963f38664ffe398827271d7f41e6Virustotal results 17.14%CoinMiner