URLhaus Database

You are currently viewing the URLhaus database entry for http://185.172.128.19/FirstZ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2750618
URL: http://185.172.128.19/FirstZ.exe
URL Status:Offline
Host: 185.172.128.19
Date added:2024-01-23 03:51:07 UTC
Last online:2024-07-05 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-01-23 03:52:05 UTC to abuse{at}tnsecurityl[dot]ltd)
Takedown time:5 months, 14 days, 18 hours, 22 minutes Bad (down since 2024-07-05 22:14:33 UTC)
Tags:64 CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-20n/aexe 145eb92a56898db2f36166c0271b859046681454c024264aed10170c34a84a3bn/a CoinMiner
2024-03-17n/aexe be4587aebd73ab69158c9c8484724cda3bfe43b3b1a405c8d7eeff0bd31ebb82n/a CoinMiner
2024-03-16n/aexe 44b153ec1309a4c33ba8f99dee81e0f5bf29b97a3207155ed41cab2cf98cf030n/a CoinMiner
2024-03-16n/aexe 719f40e0e0b7458efe469e226de1f5d03f04bad4eb69774fc16fa49a4c489c2fn/a CoinMiner
2024-03-14n/aexe 1dcb916e7ef66f1bb186bcfe2e51b2d669d3d5bc27217ef0a68859ec0a6fd70fn/a CoinMiner
2024-03-14n/aexe 7475a51b26e699cade00231079750ff7b42cbb112d13e3a9452d75baf34e43fbn/a CoinMiner
2024-03-14n/aexe 7040e3cb469275bea18bb1b9534507f0ee0180066477dd5d38420b77d5930664n/a CoinMiner
2024-03-14n/aexe 19ccd7daac627b9912e5c596a8912bff30a239e61f9a1f38d0978a6d2678bf6fn/a CoinMiner
2024-03-14n/aexe a085e17141a0f41c6c0886675bce87a48dc335445ff9cb795720543449935570n/a CoinMiner
2024-01-23n/aexe 677f393462e24fb6dba1a47b39e674f485450f91deee6076ccbad9fd5e05bd12Virustotal results 53.62%CoinMiner