URLhaus Database

You are currently viewing the URLhaus database entry for http://193.42.32.101/files/UMM.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2713195
URL: http://193.42.32.101/files/UMM.exe
URL Status:Offline
Host: 193.42.32.101
Date added:2023-09-22 05:16:05 UTC
Last online:2023-09-30 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-09-22 05:17:04 UTC to abuse{at}delis[dot]one,abuse{at}des[dot]capital)
Takedown time:8 days, 11 hours, 14 minutes Bad (down since 2023-09-30 16:31:53 UTC)
Tags:AsyncRAT link CoinMiner dropped-by-SmokeLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-30n/aexe db606ae120306c9bca7d9b71b4fadf487c2b751fd4490365e23eb1ff4f66a2f5Virustotal results 19.44%CoinMiner
2023-09-29n/aexe ca0bee4a47a24d23335eebc6cec62220d1ac2009443c455cd77d0ff0b9f8cbaen/aCoinMiner
2023-09-28n/aexe ab4cdb60909f34d673fc6bc261a54910d21ecc68ba5f591ebe5da372aca2df62n/a CoinMiner
2023-09-27n/aexe 56a70d420ecefd9ecf3103be1e075306abb0af704d28e1aad41756e4287e2a4eVirustotal results 5.56% 
2023-09-27n/aexe 9fe3bfd40d042b7a7e2d46578d5f889a90d0b0a36c233063f59fbdbb1fc5570cn/a 
2023-09-26n/aexe b23c89dc98fb361f80ae25c1d3e22fc9084f85b5c566ccdfa32c2ca0b5990ff9n/aAsyncRAT
2023-09-22n/aexe a12c63a33382720b5ce010cc050106c3909316477b956ca8c17f4a1f6ca6aa42Virustotal results 14.29%CoinMiner