URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.158.8/files/7002513081/lgfvDGw.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3590304
URL: http://176.46.158.8/files/7002513081/lgfvDGw.exe
URL Status:Offline
Host: 176.46.158.8
Date added:2025-07-26 09:43:14 UTC
Last online:2025-07-27 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-26 09:44:13 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:20 hours, 13 minutes Good (down since 2025-07-27 05:57:29 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-26lgfvDGw.exeexe e50c4d2aefb263f2e4da606094dd8fb17a09f0d53cca48a1887a97f4576fa8b7n/aCoinMiner
2025-07-26lgfvDGw.exeexe c33fb5d8d86921913f171f337722634520613940e97ca2e0a125512657c9aadeVirustotal results 44.44%CoinMiner
2025-07-26lgfvDGw.exeexe 57cda57aad00ad6f6830f2307d8602d00cc2647dcb908173d7f9bfd62a526a38n/aCoinMiner