URLhaus Database

You are currently viewing the URLhaus database entry for http://217.196.96.217/xmrig.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2722582
URL: http://217.196.96.217/xmrig.exe
URL Status:Offline
Host: 217.196.96.217
Date added:2023-10-20 02:16:11 UTC
Last online:2023-11-28 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-10-20 02:17:04 UTC to awore[dot]ru{at}gmail[dot]com)
Takedown time:1 month, 8 days, 22 hours, 27 minutes Bad (down since 2023-11-28 00:44:56 UTC)
Tags:ClearFake CoinMiner fakeupdate

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-11n/aexe eeae4c9f639f59a91e43936251b162679fbb95b48eb4b2b9f6a7c97556b1be35n/a 
2023-11-11n/aexe 8f6fe5a6bcf5cfce44ccf19b407054e20401a937fec3a4d344c1512585d85050n/aCoinMiner
2023-11-04n/aexe 7ec41b5ac025e14279389af5ea4f321b862ee86e7eb71b767ee9b62c03d842f2n/a 
2023-10-24n/aexe 6fde597f679878f61ba6e13ef0a7bfb7b6d9f8e935fc1062fdc81092d561c9ben/a 
2023-10-23n/aexe 253da4dfb8940e04f361df3811fe41c2e6c54e6972e59b6781ed639d2ca3dc83n/a 
2023-10-20n/aexe 9ef2e8714e85dcd116b709894b43babb4a0872225ae7363152013b7fd1bc95bcVirustotal results 79.17%