URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.44/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/mKM65Cf6QNqeOVw9.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3889918
URL: http://158.94.208.44/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/mKM65Cf6QNqeOVw9.exe
URL Status:flame Online (spreading malware for 2 days, 7 hours, 23 minutes)
Host: 158.94.208.44
Date added:2026-07-22 00:11:21 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-07-22 00:12:19 UTC to abuse{at}omegatech[dot]sc)
Tags:6e7868436f4d3b49f375773379ba9022 CoinMiner dropped-by-remus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-24mKM65Cf6QNqeOVw9.exeexe 4852391f807c55bf92aa89c874b739add2d284e2669a9c9c51e8e7e76882fa8an/aCoinMiner
2026-07-23mKM65Cf6QNqeOVw9.exeexe 029a364b81370e6f680886c2e1a0751cc45d1539db9ef0b9b55265def3422259n/aCoinMiner
2026-07-23mKM65Cf6QNqeOVw9.exeexe 61944cb975f79185314d23c375ad93c1d95a6b92676ef48339bea8a6adc9777dn/a 
2026-07-23mKM65Cf6QNqeOVw9.exeexe 844c176cb5a0d084602484b8a32183452818f9f16e223d29363849818fa766dbn/a 
2026-07-23mKM65Cf6QNqeOVw9.exeexe 694a3bab92e60e6760649fd40e97c04ff03faded2073e7a0c2e061229bf7820an/aCoinMiner
2026-07-22mKM65Cf6QNqeOVw9.exeexe a0493b5b7524c51c7d97757e014a35140cb61be1fdf2b620e9c5d1eb23c9cc21n/aCoinMiner
2026-07-22mKM65Cf6QNqeOVw9.exeexe e4710869dc5deaeba46756b9b65777240f714922dc9ce1a8621460abb3e69c2bn/aCoinMiner
2026-07-22mKM65Cf6QNqeOVw9.exeexe 85142e27e44b83ae26230454694d1666652e718e3764e57a1d6539c83e448402n/aCoinMiner
2026-07-22mKM65Cf6QNqeOVw9.exeexe 1501fb778e9ceefc0dca1f8cfe8c9fdd1738db5f6dbb0032348f3e161391d016n/aCoinMiner