URLhaus Database

You are currently viewing the URLhaus database entry for http://185.196.9.161/Chjirossjr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2731515
URL: http://185.196.9.161/Chjirossjr.exe
URL Status:Offline
Host: 185.196.9.161
Date added:2023-11-17 18:11:07 UTC
Last online:2023-12-04 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-17 18:12:05 UTC to abuse{at}simplecarrier[dot]net)
Takedown time:16 days, 9 hours, 48 minutes Bad (down since 2023-12-04 04:00:48 UTC)
Tags:64 Amadey CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-30n/aexe 20f894c77415be99a1f652a897af6c153de7d5994d3f233e391b1b49559ebffcn/a 
2023-11-21n/aexe f8e0ece0ff3a16a06fd53e8855b422bf3b2ced48d3facfd954526b1c6b6a42a6n/a Amadey
2023-11-18n/aexe 9bdcaf14e9f27607ce4c446a38ab2e187e0cd4f1c74176108a39c9eefa10bcb1n/a 
2023-11-17n/aexe 3f26b871b1e556d19b67814d3a758316b655cd508be014a2eea2cf40e1371b94Virustotal results 33.33%CoinMiner