URLhaus Database

You are currently viewing the URLhaus database entry for http://185.81.68.156/z.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3431114
URL: http://185.81.68.156/z.exe
URL Status:Offline
Host: 185.81.68.156
Date added:2025-02-07 16:31:04 UTC
Last online:2025-03-03 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-02-07 16:32:05 UTC to abuse{at}changway[dot]hk)
Takedown time:24 days, 1 hours, 34 minutes Bad (down since 2025-03-03 18:06:12 UTC)
Tags:exe tinynuke link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-24n/aexe 4db6590cb50ec1a718a17d5fea9dfeba7c8451f4558b893c518cf6672aedc45an/a TinyNuke
2025-02-16n/aexe bfdccf1957b1d1fcd14aa9743f69d39dbc71c4498391df1a6438f58388f3fd9dn/a TinyNuke
2025-02-10n/aexe 4d9440023af17170008531098b4a9e25f4fcfd29782c872a5e616fcb33dfa6f6Virustotal results 51.39% 
2025-02-09n/aexe 87685853e87ccc8f2d29768629ba0152b26eff9eab85364e9021d8dec4c8f5cdVirustotal results 52.17% TinyNuke
2025-02-09n/aexe 3fab10f1903deaf9f20ae86faebdababf26c99655cd7e88405748b7dce4b51b4n/a TinyNuke
2025-02-07n/aexe c401be0d8b68307e031118653a860760842713ca9763ec55050d61a2d839fca4Virustotal results 35.21%TinyNuke