URLhaus Database

You are currently viewing the URLhaus database entry for http://103.130.147.211/files/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3175044
URL: http://103.130.147.211/files/2.exe
URL Status:Offline
Host: 103.130.147.211
Date added:2024-09-15 17:52:16 UTC
Last online:2024-10-23 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: SunshineRay
Abuse complaint sent (?): Yes (2024-09-15 17:53:12 UTC to abuse{at}digiturunc[dot]com)
Takedown time:1 month, 7 days, 17 hours, 6 minutes Bad (down since 2024-10-23 11:00:01 UTC)
Tags:cryptbot exe LummaStealer opendir Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-18n/aexe 548d14789adf7f03a1a3702b7b1aba36fb5f420386ebad9678d1034c98a5aeccn/a CryptBot
2024-10-17n/aexe 5651d52584addf82b565cb5370982ebb42d02ea40a93a9e511092fb582005df4Virustotal results 34.25%CryptBot
2024-10-16n/aexe 973a2e2e7f9c31d20204af94689d261d56e646c00b29121709035070b0069220n/aCryptBot
2024-10-15n/aexe 4c8c3f524f350623db99f862011a87da14cd9b88a87cb334293bc38f227b0d9en/a CryptBot
2024-10-12n/aexe 20061bce629f4e86cb50cb6464e28b3ddd2d0a31be41a5962e2cf439386ac730n/a CryptBot
2024-10-11n/aexe a2fea9a71351db0106fc4f75a6fa43e45fb5b6c8499867b79f2a8c81b3038375n/a CryptBot
2024-10-09n/aexe 764771334026af81481db7b74bf0b725463a77ad721c07e649173741837a1cbfn/a CryptBot
2024-10-08n/aexe 353927fb2898c70a09305393c6a63cd1345e2462588f58352503bd11ff9b99ban/a CryptBot
2024-10-04n/aexe 432f4077d2f9d7e37290e2baef855ed9943712c40808ba1394892c61275b57ccn/a CryptBot
2024-10-02n/aexe 7178bba0d8a49e05390d2aeeb204168f646dc3d3869a09743729fd8b4f1cc7edVirustotal results 12.68% CryptBot
2024-10-02n/aexe 496f1637d320485bf77b29de0185e5c953636ffdd2a8b25e66a495e477f6db9cn/a CryptBot
2024-10-01n/aexe 04cd12393aa1e04aaca2f1f05a0da8ea1b0003a01a66dfc863991034f836f45aVirustotal results 22.54% 
2024-10-01n/aexe 0e2790b58ae8f3d43c184979e354fd415e990488d7e4a3f5c8aacfc5d0f1ed68n/aCryptBot
2024-09-29n/aexe 7451a7613a173ab1c80d664892cb744c7f09925dedf9adb964b31861b74cb713n/a 
2024-09-28n/aexe b39525df56e9d5f26067add74133154b651ca91d4201302ce505444d00ac6693n/aLummaStealer
2024-09-28n/aexe 8a110fc1c281956d35eb86bc887359bbbf933c9a7ce3185940c65682cfc28084n/a CryptBot
2024-09-27n/aexe ff26742815c194fb24443f99d7c7a06c584a9e7f68c774fb1c0a078b8785ac43n/a CryptBot
2024-09-27n/aexe 69b153cd6176d790d2aae37ccc5600bde475a0eca6d1f6f531a1e040d44bccd1n/aSocks5Systemz
2024-09-27n/aexe 17ae975bc89c6255bb747b81a28199bd962643f706121ab98b2112f015a9a087n/aCryptBot
2024-09-25n/aexe 7fbf48d0029650b48af23fa6d7d02cd783cdf679e369ea43a7040c8f3dbb6015n/a CryptBot
2024-09-24n/aexe fcfb14707aa5abe3cf84d6059717246e6593cd43d60c609fe3095825827637c7Virustotal results 42.47% CryptBot
2024-09-23n/aexe a89687d296782db168a92a496fb865d481666cf53588684f69ecac509711da16Virustotal results 41.10%CryptBot
2024-09-22n/aexe a8a451b18143b192de1f6da327400e4fe0b629386d0c9dbf0d77e002e8ca6610n/aCryptBot
2024-09-21n/aexe 5aec1cb903ac8b2b877603083a838004cd139caf58f4212e8d7c371f19e17b7cn/aCryptBot
2024-09-20n/aexe 7febc09c97d078d9617d71db6c6c41ed7f81fd332a01b7683108c453661d3ca8n/a CryptBot
2024-09-20n/aexe d06176d8dada517e04df25f3af5ebb2bd21a73c760ad52bd7229017dc07f0fa5Virustotal results 41.67%CryptBot
2024-09-16n/aexe 638dd1f701aec57c51765e330c7c4664d8913cb3d0e54bb1c102bdbe30452eccVirustotal results 57.53%CryptBot
2024-09-15n/aexe 5c5ce4bf348150622adb9f71ed42879c4a5ebf99c94c2be940141d28f2c8275dVirustotal results 0.00%
2024-09-15n/aexe c82abbbb220c14d9cc072df169871d93906354a0f87b69eff8b5ab6863c93987Virustotal results 43.84% CryptBot