URLhaus Database

You are currently viewing the URLhaus database entry for http://91.239.211.89/bins/kworkerd-rcu which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3868021
URL: http://91.239.211.89/bins/kworkerd-rcu
URL Status:Offline
Host: 91.239.211.89
Date added:2026-06-20 05:58:09 UTC
Last online:2026-06-26 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-06-20 05:58:19 UTC to absue{at}versionblue[dot]de,report{at}abuseradar[dot]com)
Takedown time:6 days, 8 hours, 3 minutes Bad (down since 2026-06-26 14:01:53 UTC)
Tags:CoinMiner ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-26n/aelf 4225c73c7a0f0cc9512662bff169b8a772044bc7f7a72b1b0e241f946af7f60an/aCoinMiner
2026-06-25n/aelf 6dda8bd9e921d845c95831fd24ab7e9172cc2971d3ae6cc5d810e56e979fb763n/aCoinMiner
2026-06-21n/aelf 5c72bdfe8c816a153926f00cb2c34c21352570e00a43df9e0fab939cd5a3889bn/aCoinMiner
2026-06-20n/aelf ae5db9eb1406557f12e2d9b474b2519beba3b6fc6afdb8ded74f41d258ae82cdn/aCoinMiner
2026-06-20n/aelf 77bf85c043145dd34d7069fff7c3924074303294396ba775c070d1ff2c3a1e80n/aCoinMiner