URLhaus Database

You are currently viewing the URLhaus database entry for http://15.204.38.240/files/Akh.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2781338
URL: http://15.204.38.240/files/Akh.exe
URL Status:Offline
Host: 15.204.38.240
Date added:2024-03-12 10:26:10 UTC
Last online:2024-03-18 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-12 10:27:08 UTC to abuse{at}ovh[dot]net)
Takedown time:6 days, 3 hours, 26 minutes Bad (down since 2024-03-18 13:53:22 UTC)
Tags:CoinMiner dropped-by-PrivateLoader Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-17n/aexe 3c3fcc09bcc385c0b3f4ec53a4997a8402dfb35ff0ee0c73cf59b40da068a212n/a 
2024-03-16n/aexe 662a0775782305aab0ab92f0e9bc678df59db91e4ec7b7f9e201d0307932ec45n/a 
2024-03-15n/aexe d8f1979b2b2a3d59db7716e40738d5d2a3d557055831e54f8e1f52079dd04aa5n/aStealc
2024-03-15n/aexe ba068821f1642d1ef0496c9614cc953d538fdb3adeca1b9235a8ff60648a704dn/a 
2024-03-14n/aexe 7860ba1f015ecc2e29a9c2aa99172c9fadd5bcde68e6f2a8a66095e88f29ff5cn/a 
2024-03-14n/aexe 08b8633507bbabd427439f1fb9ce13335c1eb082aa9f9d02b3331020e854a856n/aCoinMiner
2024-03-13n/aexe 240675a2b1de7df228e776969a6d9d651bc8097254e88c07a8d19f6ce0edd1ecn/aStealc
2024-03-12n/aexe 3cf0b82b4b91ac001ede7dfe7736f42e2a5e1bd9cc6da34393ec9e18ec81a9fen/aStealc