URLhaus Database

You are currently viewing the URLhaus database entry for http://enfantfoundation.com/netTime.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715541
URL: http://enfantfoundation.com/netTime.exe
URL Status:Offline
Host: enfantfoundation.com
Date added:2023-10-01 20:30:19 UTC
Last online:2023-11-02 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-02 17:47:05 UTC to abuse{at}confluence-networks[dot]com)
Takedown time:1 month, 2 days, 19 hours, 2 minutes Bad (down since 2023-11-03 15:33:33 UTC)
Tags:CoinMiner dropped-by-PrivateLoader Phonk

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-06n/aexe 1f87cc53b65d230d000fb5332e3d13a01bae16ed20c81656f5dc30a440daaf84n/aCoinMiner
2023-10-04n/aexe 92b9dbef2c0414a2e5f09e2a419a80ba9feb628761a6b07d14fb885b2fa22b60Virustotal results 33.33%Phonk
2023-10-03n/aexe 343ed81c3b97f9cff2d0ae5fe734dd1849d4d0fd3dd3887cde9ca4186ef91a47n/aPhonk
2023-10-02n/aexe d273d63ec7562e27003ad53db329429452d86faef87b6d64b72875cdb1dd3ceen/aPhonk
2023-10-01n/aexe 402f8ae71cdd4c4a8ddcbeb123879824d9c40bd6d8c8d04f1e6575c049105eeaVirustotal results 40.00%CoinMiner