URLhaus Database

You are currently viewing the URLhaus database entry for http://85.217.144.143/files/UMM.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715114
URL: http://85.217.144.143/files/UMM.exe
URL Status:Offline
Host: 85.217.144.143
Date added:2023-09-29 17:18:05 UTC
Last online:2023-10-02 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-29 17:19:04 UTC to abuse{at}delis[dot]one,abuse{at}des[dot]capital)
Takedown time:3 days, 0 hours, 49 minutes Bad (down since 2023-10-02 18:09:00 UTC)
Tags:32 Amadey CoinMiner exe fabookie

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-02n/aexe 3fc7a638c089e78aaa0b97f39791a8ac3369f802dac968d1a5300eaba7e7d29bVirustotal results 21.67%Fabookie
2023-10-01n/aexe 3193a9adfee944d12a081b3fd327d714aa8a3aece4cbf8bfbfd415d9f0574975Virustotal results 23.61%Fabookie
2023-09-30n/aexe b4bddd5fafbf9762c15cae6dea7fde35361ee8881c5d707523a0c21c15a80d1dn/a 
2023-09-30n/aexe 15d27c669c13bcb799ef7b656ee45944469650b8c2821de397d3dc4ae9740f67Virustotal results 15.49% Amadey
2023-09-30n/aexe db606ae120306c9bca7d9b71b4fadf487c2b751fd4490365e23eb1ff4f66a2f5Virustotal results 19.44%CoinMiner
2023-09-29n/aexe ca0bee4a47a24d23335eebc6cec62220d1ac2009443c455cd77d0ff0b9f8cbaeVirustotal results 36.11%CoinMiner