URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.32/files/5373782173/QvG0bbo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3577559
URL: http://176.46.157.32/files/5373782173/QvG0bbo.exe
URL Status:Offline
Host: 176.46.157.32
Date added:2025-07-06 14:00:08 UTC
Last online:2025-07-20 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-06 14:01:11 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:14 days, 4 hours, 21 minutes Bad (down since 2025-07-20 18:22:30 UTC)
Tags:CoinMiner donutloader exe PureLogsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-17QvG0bbo.exeexe f36674f9db078dd2d1c94fd56aa63a2933f7c765e61e7281756955dbcb033388Virustotal results 43.66% DonutLoader
2025-07-17QvG0bbo.exeexe 918c82ab8f58cdc730927520ef696c842bc0cba84ff787f816dbd7a62711272fVirustotal results 41.18%CoinMiner
2025-07-17QvG0bbo.exeexe 34aac76eadf209001ce997d584e5f94d480438426558d1b2c06eb24087bd03e4n/aPureLogsStealer
2025-07-14QvG0bbo.exeexe 1b7f06162b9c2dedd309a402ab75e16ce792d93645ed232ca65a312e3e395efaVirustotal results 51.39% 
2025-07-06QvG0bbo.exeexe 35ec950215ab50445813e2babef90dafe6c2f7e6dd4e8a70418cb48ab61358eaVirustotal results 54.17%PureLogsStealer