URLhaus Database

You are currently viewing the URLhaus database entry for http://195.20.16.153/conhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2736330
URL: http://195.20.16.153/conhost.exe
URL Status:Offline
Host: 195.20.16.153
Date added:2023-11-30 05:43:10 UTC
Last online:2024-05-04 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-30 05:44:04 UTC to support{at}zerohost[dot]network)
Takedown time:5 months, 6 days, 14 hours, 41 minutes Bad (down since 2024-05-04 20:26:01 UTC)
Tags:32 BVnUqo--FernandoKappuccino CoinMiner exe Lumma

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-19n/aexe daa12f98ca994577051fe3d1bbfdaa03a73e61ab7610d2504314c59184f390cdn/a 
2024-03-16n/aexe 48c6857cde2b97fc7701aa1b131aafe868961cd7c6eba927006070dd154c8badn/a 
2024-03-15n/aexe a83b007c0c8a265bbd6ec9b1c36d102b2969a35e978b11307993227993b7df64n/a 
2024-03-14n/aexe 7b7a3a3e6736de1747c90f8d5e4824d2832be7628d4e82bbac2725b2771e47c0n/a 
2024-02-19n/aexe efee38133480e7ccaa11424d49bb3d8ebdb89ffb1d81a10f6c405337e7d3a737n/aCoinMiner
2024-02-19n/aexe 8072a80ce4455f461cc10d67b486f2d436d42b2dd2165628a1e91a70b50fdb4bn/a 
2024-02-19n/aexe edb8b0f5765a8de5f294a0e6661a30dc70ced554c0d83449481c0937dbf89096Virustotal results 76.47% 
2024-01-11n/aexe 3e26cca96dfc289361a1d439f437b60a85c8398a1a200a18c9ab87679ff524d6n/a CoinMiner
2024-01-01n/aexe b57fe599791c010401a65bd6064dfd0ea26c71853999077198056bb821a8d1a4n/a CoinMiner
2023-12-22n/aexe 3b655b9755ffb770c5beaee783dd1c4a393137a77e1c1c0bf504e4d3f0bdd1d1n/a 
2023-12-16n/aexe 785d5af67c6cfbb5a7bee0babfe2e818fded674f968f8d9c3bb4b76e138f46bdn/a CoinMiner
2023-12-11n/aexe 93b23a6c53538ac84e7d374ad19c7e427f04e08ae3ebb72c8c6ee8f125c4b33cn/aCoinMiner
2023-12-08n/aexe b13b5f0d96bfd285bcc3285d12217bea50347549a6048973f033edf03696ec13n/a 
2023-12-06n/aexe 8257b6d9db2a0054895b3afaf01e40a3dfb56bdf7195865097201cc6c1e38edfn/aCoinMiner
2023-11-30n/aexe 3ce7038bba7b55be98005d471b7ad1c9166047a14bbfa016d1bb3b58960e6c1an/a CoinMiner
2023-11-30n/aexe a12690c6e82e3139977a17c976b49355878b0bfdeb07a142f313da289b5d5c1cVirustotal results 69.01%CoinMiner