URLhaus Database

You are currently viewing the URLhaus database entry for http://91.239.211.89/bins/kworkerd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3868020
URL: http://91.239.211.89/bins/kworkerd
URL Status:Offline
Host: 91.239.211.89
Date added:2026-06-20 05:58:09 UTC
Last online:2026-06-26 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-06-20 05:58:19 UTC to absue{at}versionblue[dot]de,report{at}abuseradar[dot]com)
Takedown time:6 days, 6 hours, 55 minutes Bad (down since 2026-06-26 12:54:13 UTC)
Tags:CoinMiner ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-26n/aelf 8c869f9982c38d7f0cbfc5ddb1e489d3a8c94ed0cb19b8d9af27e329dd6a61adn/aCoinMiner
2026-06-25n/aelf fb1f408e089ca5346d31e07ab1d821b1b19f1488ed8eaad587f421e2d3689fa4n/aCoinMiner
2026-06-21n/aelf 0343cc89b06f7a6e45cb7d09f0328821c826d63216265d5d0c0a22902af835d1n/aCoinMiner
2026-06-20n/aelf c1e97858d11f97a0157f31aeb413c76ecd9cd96062929e2e659ae9e3c0dc78c4n/aCoinMiner
2026-06-20n/aelf 036283407ccf8ecff4105810b91c1faf6f17c138e77f28d0ef0f3109b22ef785n/aCoinMiner