URLhaus Database

You are currently viewing the URLhaus database entry for http://134.122.178.123:99/nginx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:941921
URL: http://134.122.178.123:99/nginx.exe
URL Status:Offline
Host: 134.122.178.123
Date added:2020-12-25 08:33:04 UTC
Last online:2021-02-21 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-25 08:34:10 UTC to abuse{at}rackip[dot]com)
Takedown time:1 month, 28 days, 2 hours, 10 minutes Bad (down since 2021-02-21 10:44:56 UTC)
Tags:exe hfs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-26nginx.exeexe 0175a29f801ef7a555c3d20744a5fa5336604d420d8ffe98bb5723744d1a82cdVirustotal results 74.65%RunningRAT
2020-12-26nginx.exeexe 9b1367b0da26125af6946a108e9e657c373ad4e25be8e9a9eaa3a29adf6c95d9n/aRunningRAT
2020-12-25nginx.exeexe ef03a58568ec094636fe33261e1fafbb6aa77125be68c3615da4823abba198d8Virustotal results 76.06%RunningRAT
2020-12-25nginx.exeexe 435a836a250603d3014f794b7123a5ed21d5481a4a86c10d669e8b1f71e9f113Virustotal results 77.46%RunningRAT