URLhaus Database

You are currently viewing the URLhaus database entry for http://a0920080.xsph.ru/miner.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2786779
URL: http://a0920080.xsph.ru/miner.exe
URL Status:Offline
Host: a0920080.xsph.ru
Date added:2024-03-19 08:27:26 UTC
Last online:2024-04-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-03-19 08:28:04 UTC to abuse{at}sprinthost[dot]ru)
Takedown time:1 month, 5 days, 3 hours, 38 minutes Bad (down since 2024-04-23 12:06:44 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-14n/aexe b3f918b9fcb1fce6d2f6e51f4281bcd7fb6716b7dc003e28322c1ab462c257f2n/a 
2024-04-01n/aexe babf06b7733ab2e29c11f6f25b23a0ec5b706f096dcf8b3284b141ffbf460428n/a 
2024-03-26n/aexe c03d932ba38710c6130f5feaba9845431127f201bf6a55b0b06467e33d14fcd0n/a 
2024-03-26n/aexe ef368e4190c79c1ad2da858ac321702079f919bd8df45de119b395cbd3194aa9n/a 
2024-03-20n/aexe ad598d5de7674567821da09334994189cb981f9f910250a31af532f97b7fd29dn/a 
2024-03-20n/aexe 0ce0958fe1e100dc660a531cd79e76b687eeb78775feee641d06ef9290d754f5n/a 
2024-03-19n/aexe e926101ef3e4d6cf95d402af21eaf7d03bbf775b8acc3a98f221002052e8fccbn/a 
2024-03-19n/aexe 0349c630bab4307a0b32c2becb1c43118e8fd9f418783ed2442bd3c37c23602cn/a 
2024-03-19n/aexe 01d46b910e5e5c0bee77e27f190ace46674465c95267d6ba7744d39cf76ed144Virustotal results 29.58%CoinMiner