URLhaus Database

You are currently viewing the URLhaus database entry for http://45.141.233.196/files/7002513081/ls1FDZl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3594027
URL: http://45.141.233.196/files/7002513081/ls1FDZl.exe
URL Status:Offline
Host: 45.141.233.196
Date added:2025-08-01 06:14:17 UTC
Last online:2025-08-02 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-08-01 06:15:20 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 day, 5 hours, 59 minutes Poor (down since 2025-08-02 12:15:11 UTC)
Tags:c2-monitor-auto CoinMiner dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-02ls1FDZl.exeexe 838ede69630299c86da1935a1f7a99fd9c63d5eb9a2a31f2d74472ce61485d4fVirustotal results 18.06% CoinMiner
2025-08-01ls1FDZl.exeexe b628afe7cec601bf04feacde152f6097848b0e40913f1fe54b180a2bf6a50c75Virustotal results 18.06% CoinMiner
2025-08-01ls1FDZl.exeexe 756235031cf91ae9228b774935470350336943fc7afbfbfdc826d47ae66be020Virustotal results 20.59%CoinMiner
2025-08-01ls1FDZl.exeexe 8c87945a6f9838d03ec714a60e12ab80bdd980ee43ea170f6b5d1e2acd294babn/aCoinMiner