URLhaus Database

You are currently viewing the URLhaus database entry for http://cnc.c25e6559668942.xyz/DarkIRC.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:878315
URL: http://cnc.c25e6559668942.xyz/DarkIRC.exe
URL Status:Offline
Host: cnc.c25e6559668942.xyz
Date added:2020-12-01 04:50:39 UTC
Last online:2020-12-23 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-01 08:44:05 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 11 hours, 16 minutes Bad (down since 2020-12-23 20:00:14 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-15n/aexe 5410d7889b211491b0264d4ab830d002fe76f0384b4b5443a5b5c0d3210a4af3n/a 
2020-12-15n/aexe ef9b790a48506fc5221fcccd70290b55d282bc4b1cd4adb9c29fbdfb9bf8861cn/a 
2020-12-12n/aexe 1b6c705a53af69a0afba92a62a55393e48c7a4d578cd51ef0c096f1877881229Virustotal results 62.86% CoinMiner
2020-12-02n/aexe def3f8797891579623385136838b1526096afc2bf01f9a08e27aa2073b6d7539n/aCoinMiner
2020-12-02n/aexe 177d8488609bff9254995b0828ef938465746d8f968dd52793d38c1882453e84n/a CoinMiner
2020-12-01n/aexe fb7deb0328e723aa3cdf6f884887b32d04dd462bbccf35dd42c56ca4717e8aceVirustotal results 46.38% CoinMiner
2020-12-01n/aexe 954b8a41846d4407d815f0969dadcc969b0a1404e5c2c3f6ae6d1d602d7af842Virustotal results 44.44% CoinMiner