URLhaus Database

You are currently viewing the URLhaus database entry for http://worm.ws/32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:621240
URL: http://worm.ws/32.exe
URL Status:Offline
Host: worm.ws
Date added:2020-09-29 06:32:05 UTC
Last online:2021-05-25 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-29 07:10:17 UTC to abuse+grandcosmetic2[dot]ru{at}crex-fex-pex[dot]ru)
Takedown time:7 months, 28 days, 0 hours, 29 minutes Bad (down since 2021-05-25 07:39:29 UTC)
Tags:CoinMiner CoinMiner.XMRig exe phorpiex link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-24n/aexe 5e31f3d2ad06413f4c3824c6bbe56cf7dffda38cec5bd1b2c0c377718a11297cVirustotal results 54.29%Phorpiex
2021-05-03n/aexe ad74f606e358fb7f6db9a5652d0a60310d069ac108934a72d0352e5fa9248b38n/aPhorpiex
2021-04-28n/aexe 057f8f82fb2bae7638438cdd9ae6099f06039d0af97564b7bad9486066b78505n/a Phorpiex
2021-04-22n/aexe 23e021448870b402726a21b4c9121fc5fd3ba6aa2cad432dbb190faa9013f352Virustotal results 41.18% Phorpiex
2021-04-13n/aexe 7f6fd29408e25032cf1a98202b8525472745042b10fefb007c040f1c65bae9acn/a CoinMiner
2021-02-04n/aexe 78bb6fe6bde75a9ba11d0d2f69306619290f90aa94448d6aa4da340d2144e1cbn/aPhorpiex
2021-02-03n/aexe 329ea43f5027e79bb3151ce827fadbc6173a84218fd984ae4a4b44b478411339n/aPhorpiex
2021-01-21n/aexe fdacb26b6a7da038edf12cd0d8bbdcfeae66a0dd6e97a94799e77f0e14740dadn/a
2021-01-21n/aexe 2dc0e02fcc1a56c81903905869a396f328813e63eba46f941ff3379430e12d12n/aPhorpiex
2021-01-05n/aexe 7c419f22e51f37be0c483bbf3c320c40b6939785896b756c504af5de5b46237fn/aPhorpiex
2020-12-30n/aexe 7e663d31d2d1fb89bb88dfa65fea415d754e5a9e6d804cf99c59d98f95580945n/aPhorpiex
2020-12-16n/aexe 9ede66863b43a80a99cb77abbaf1a35283d0e9e420b64cc669a5201e975ccc76Virustotal results 62.32% CoinMiner
2020-11-03n/aexe d8489f43ed8b96cd5f5b28f6e570dbb57571656869c7b0a8ba215fb375857070Virustotal results 54.29%Smoke Loader
2020-10-31n/aexe 5d9b6c49a8c84b01122da49a1237c880e2eb71d44f264e8a0effc56b7b586bf6Virustotal results 54.17%Phorpiex
2020-10-24n/aexe f2af7f2de72d42d045309ea26b6c19076a42b4e6703fb15b5d40416ab37a8052Virustotal results 59.68%Phorpiex
2020-10-22n/aexe b9d9218aca35322d383f7bb5e914422472bc8159de44a8ee7bb66b9e871b5d80Virustotal results 72.46% CoinMiner
2020-10-11n/aexe c2dccbab233df2db2afa8be9c811ca05f44befb91cdd82057e3877367f7902dcVirustotal results 62.86% CoinMiner.XMRig
2020-10-05n/aexe f91d9235179ccc179d346971cdf19b941a151a2f70ff7680e35fca9feda5874cn/a
2020-09-29n/aexe e2a0a85c3ad93e14292ed2472855d157317f48abcde859c81d51dd42816be065Virustotal results 78.57%Phorpiex