URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.19/inc/2020.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3067445
URL: http://185.215.113.19/inc/2020.exe
URL Status:Offline
Host: 185.215.113.19
Date added:2024-07-25 23:14:17 UTC
Last online:2024-10-25 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-07-25 23:15:11 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:3 months, 1 days, 18 hours, 30 minutes Bad (down since 2024-10-25 17:45:45 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-20n/aexe fa52c2d959ea5775343d0490cff4e064a4155abc6c5b97903a147d2aac1bacaen/a CoinMiner
2024-08-22n/aexe 7e99b25771dcbb096c98a63c816be5e2bd1d962bd6e6d1d5940fc077470b40ban/a CoinMiner
2024-08-13n/aexe 5570fba1ad8c82156414d60aad883160c643fed48cf5237ae5ea13257b315895n/a CoinMiner
2024-08-09n/aexe b172bc3565aee317701606a7b93fa21927d05d7f73330ac4b153a3af3f9b22e2n/a CoinMiner
2024-07-25n/aexe 6f2964216c81a6f67309680b7590dfd4df31a19c7fc73917fa8057b9a194b617Virustotal results 45.33%CoinMiner