URLhaus Database

You are currently viewing the URLhaus database entry for http://103.93.252.167/web3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:384151
URL: http://103.93.252.167/web3.exe
URL Status:Offline
Host: 103.93.252.167
Date added:2020-06-08 19:37:30 UTC
Last online:2020-06-13 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-06-08 19:38:02 UTC to abuse{at}beyotta[dot]net)
Takedown time:4 days, 18 hours, 43 minutes Bad (down since 2020-06-13 14:21:22 UTC)
Tags:CoinMiner exe nitol link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-12web3.exeexe 4f5e5f38185cb40b5cb7a04c1aaa2f5aec69dfc23293658cf92f22fd747b27a5n/a Nitol
2020-06-11web3.exeexe bea307fee4afeda590550fbc6adba01fdcd25320c3b4705dd85016c3c90e83e9n/a CoinMiner
2020-06-11web3.exeexe a2f899626365237b9096fc6fbc8c0b66c700358f98d6530b6860c9a7ed40e8e0n/a Nitol
2020-06-10web3.exeexe f17ba2066c3d93959204130e2dc4466cf109b7cd5f42f47d942dd6acffd3c05eVirustotal results 51.39% Nitol
2020-06-08web3.exeexe b1c7d1ea4c5e4547ca50cfb7a3f27fa667a8778a154bd49446b2cfc738827f60Virustotal results 55.71% Nitol
2020-06-08web3.exeexe 6de1ce049ca1c37daf392751ee6d32e4f2dbc31cdfb18ac1c6449b0b89cc8f58Virustotal results 51.43%