URLhaus Database

You are currently viewing the URLhaus database entry for http://103.130.147.211/Files/22.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3204693
URL: http://103.130.147.211/Files/22.exe
URL Status:Offline
Host: 103.130.147.211
Date added:2024-10-02 06:47:11 UTC
Last online:2024-10-07 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-02 06:48:08 UTC to abuse{at}digiturunc[dot]com)
Takedown time:5 days, 4 hours, 9 minutes Bad (down since 2024-10-07 10:57:51 UTC)
Tags:cryptbot dropped-by-PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-07n/aexe 8e55a07b9a3056a77b85b712d059e878ca3e455f2c32c8092f7427661db0912an/a CryptBot
2024-10-04n/aexe bc33badea9ccccd82318804b9de1b04d0f75485961c4fa3389e5dd7d959145a9n/a CryptBot
2024-10-03n/aexe 9ef0c7390cc061b8b11fb1d7828d7521271f7709061b254471b77bc54cea322fn/a CryptBot
2024-10-02n/aexe 7178bba0d8a49e05390d2aeeb204168f646dc3d3869a09743729fd8b4f1cc7edVirustotal results 12.68% CryptBot
2024-10-02n/aexe 496f1637d320485bf77b29de0185e5c953636ffdd2a8b25e66a495e477f6db9cn/a CryptBot
2024-10-02n/aexe 0e2790b58ae8f3d43c184979e354fd415e990488d7e4a3f5c8aacfc5d0f1ed68Virustotal results 40.28%CryptBot