URLhaus Database

You are currently viewing the URLhaus database entry for http://103.130.147.211/Files/Channel2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3187775
URL: http://103.130.147.211/Files/Channel2.exe
URL Status:Offline
Host: 103.130.147.211
Date added:2024-09-23 14:46:04 UTC
Last online:2024-10-01 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-24 16:12:07 UTC to abuse{at}digiturunc[dot]com)
Takedown time:6 days, 21 hours, 56 minutes Bad (down since 2024-10-01 14:08:38 UTC)
Tags:cryptbot dropped-by-PrivateLoader encrypted LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-29n/aexe 61df90fe6cbadebdeb242e44f84228ee1178f56b92a349c0e547562c5730cd24n/a 
2024-09-28n/aexe d73bea0eaec1c09fe508f58746a99586c3369be41d08845ba12764a4b2f2a147n/aLummaStealer
2024-09-28n/aexe 8a110fc1c281956d35eb86bc887359bbbf933c9a7ce3185940c65682cfc28084n/a CryptBot
2024-09-28n/aexe 290853a79ea4b4292ab9996a1d10616c120989df2585c702ddaca90daf92328an/a CryptBot
2024-09-27n/aexe 17ae975bc89c6255bb747b81a28199bd962643f706121ab98b2112f015a9a087Virustotal results 52.05%CryptBot
2024-09-26n/aexe 7fbf48d0029650b48af23fa6d7d02cd783cdf679e369ea43a7040c8f3dbb6015n/a CryptBot
2024-09-24n/aexe c671e33f6757cef930713d2e4efeb8642177675e95fc05de92e124213022a00bn/a CryptBot