URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.66/xmr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3374853
URL: http://185.215.113.66/xmr.exe
URL Status:Offline
Host: 185.215.113.66
Date added:2024-12-24 07:17:09 UTC
Last online:2025-03-08 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-12-24 07:18:16 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:2 months, 14 days, 5 hours, 50 minutes Bad (down since 2025-03-08 13:09:14 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-26n/aexe 4b8f652ca183784f370a57243e127fe7e6bfec64bab0f364780f88db00179488Virustotal results 62.50% CoinMiner
2024-12-25n/aexe ef056675a16305ab5308e3b8526b5e8db1f1510036ad22cb14b4b6260cc90a0dVirustotal results 61.11% CoinMiner
2024-12-24n/aexe 9285ce9490678ad7f20218cf77c48fecc2f0deaad292943f360d6e6c257d1f2bn/a CoinMiner
2024-12-24n/aexe 7ffa03be49bf2b8bc9a184baacea683be6059bd3d99f7ed7e6625c6183161136Virustotal results 66.67% CoinMiner