URLhaus Database

You are currently viewing the URLhaus database entry for http://cnc.c25e6559668942.xyz/mine.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:878149
URL: http://cnc.c25e6559668942.xyz/mine.exe
URL Status:Offline
Host: cnc.c25e6559668942.xyz
Date added:2020-12-01 03:42:37 UTC
Last online:2020-12-24 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-01 04:46:07 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 19 hours, 31 minutes Bad (down since 2020-12-24 00:17:31 UTC)
Tags:CoinMiner exe IRCbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23n/aexe 6ad0b6bd4a9e437166322ffaac45217c54e51c2de046e37d1199ec1c777e18dbn/a 
2020-12-21n/aexe 0de4a78404ed0c891ecebf029704c26d7c2f48a739eafb64d2a176c68210958fn/a 
2020-12-21n/aexe f0df31f07e5fb19fbe5a3f24a6260a6274b112b3e04b9f5f0a326d78d13d97b1n/a 
2020-12-20n/aexe 5fc89085d6a6bd19136bf7983706ef6e4f74007e42dfa5361fe30a57a5eb392dn/a 
2020-12-20n/aexe f6214a49ae62129003a597a6f20ca5e2cd4889853d453eac5e7b37e89669356bn/a 
2020-12-20n/aexe 9f728223dbe860aae752706f67c389af0e9b1b444450a204d2ea8b46b7043594n/a 
2020-12-20n/aexe 23640c39e965e440f1517c0da7a159f1962906f685ab1372e65cc843234eaf55n/a 
2020-12-15n/aexe 9915c580ab47809bed8f0fa2f0d7d0d8870b06c5eb8c1fbd2db32e07126c2ec2Virustotal results 54.93% CoinMiner
2020-12-07n/aexe 16567bc7fdda568f2bc0792989ce6a71e17d56f5e4fefe4263dfa106e90f16ffn/a CoinMiner
2020-12-03n/aexe 24b8c374dce7769530f56f2dd510bc766b238cb1fd4b3ef4fb082e435d0666d6Virustotal results 47.89% CoinMiner
2020-12-02n/aexe c7f6ad7d3e040d26e8103885756e2f720a97a16f12ef44bf6707676d26680586n/aCoinMiner
2020-12-02n/aexe 18ffa0d7451177eb84dab5a2e027daa917da88cd9ccf5393b49711e4a363fa3fVirustotal results 30.43% 
2020-12-02n/aexe 37e034940cd4c2e314bfa6c6e523debb1064d22440352a9ebfe1d8837c2ef22fVirustotal results 42.86% CoinMiner
2020-12-01n/aexe a8810cebe3e7cdebcde451d45705eff4c6f5fc3cbdaba5386c8d77574b04df10Virustotal results 35.71% IRCbot