URLhaus Database

You are currently viewing the URLhaus database entry for http://jask.powerforxes.shop/lopsa/66c6efd6b6f8b_123p.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3211967
URL: http://jask.powerforxes.shop/lopsa/66c6efd6b6f8b_123p.exe
URL Status:Offline
Host: jask.powerforxes.shop
Date added:2024-10-04 19:00:06 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 19:01:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 22 hours, 15 minutes Bad (down since 2024-10-22 17:16:23 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-19n/aexe 345b301b125b5052146acd908856875e0a426c6e0e0557e9f46d0ea2e690de43n/a 
2024-10-16n/aexe 9c8072b4dea54bf652bc432d860a4a2857f426dbfb754a3d04f6e08c208c0319n/a 
2024-10-14n/aexe 306fead4a98c7927fd7cc09d425d9bc5194d7331de0f00a65e9a81baf3fa8ef4n/a 
2024-10-14n/aexe 459486390e71deb8df452e003250440f87485d380e342a439571912fb5bb0609n/a 
2024-10-12n/aexe 606c009f90128913cdb29035ca9e6fa4ff7c9496568c42e3345c02c3caa810fen/a 
2024-10-09n/aexe 7902f47364eae848a33338331f5b271e20ce6d0d6b3301b160f5e3ca81915c68n/a 
2024-10-08n/aexe 3fe6909a670dc8857ba883901fe096110fea905024dddc5302cfc1301f5ac4ben/a 
2024-10-04n/aexe 7870d51e2ec6a82fede5bcb9a3dd55c530354b9847b1342e15bfd9f6dc5b40fbVirustotal results 76.06%CoinMiner