URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.215.113.36
Firstseen:2021-09-28 18:07:03 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-12 19:29:16http://185.215.113.36/Javvvum.exeOfflinecryptbot abus3reports
2024-11-09 05:17:06http://185.215.113.36/AllNew.exeOffline32 Amadey exe zbetcheckin
2024-11-03 10:39:06http://185.215.113.36/2927.exeOfflineexe abus3reports
2024-11-03 10:39:05http://185.215.113.36/Newofff.exeOfflineexe abus3reports
2024-11-03 10:35:08http://185.215.113.36/Office2024.exeOfflineCoinMiner exe abus3reports
2024-11-03 10:34:07http://185.215.113.36/exbuild.exeOfflineexe abus3reports
2024-11-03 10:34:06http://185.215.113.36/Nework.exeOfflineexe abus3reports
2024-11-03 10:02:13http://185.215.113.36/JavvUm.exeOfflinecryptbot abus3reports
2024-11-03 10:02:09http://185.215.113.36/stail.exeOfflineSocks5Systemz ext abus3reports
2024-11-03 07:15:13http://185.215.113.36/JavUmar.exeOffline32 cryptbot exe zbetcheckin
2024-11-01 16:46:17http://185.215.113.36/Offnewhere.exeOfflineAmadey cryptbot exe abus3reports
2022-01-11 07:37:04http://185.215.113.36/windowshelper.binOfflineencrypted abuse_ch
2021-09-29 13:15:10http://185.215.113.36/zenaaaretest/UpSys.exeOffline Cryptolaemus1
2021-09-29 10:15:01http://185.215.113.36/zenaaaretest/Zenar_protec...Offlineexe zbetcheckin
2021-09-29 09:24:35http://185.215.113.36/DebasedSeptenary_2021-09-...Offline32 exe RedLineStealer ext zbetcheckin
2021-09-29 06:55:37http://185.215.113.36/zena/UpSys.exeOffline Cryptolaemus1
2021-09-29 06:55:05http://185.215.113.36/Zenar_protected.exeOffline Cryptolaemus1
2021-09-28 19:05:05http://185.215.113.36/DebasedSeptenary_2021-09-...Offline32 exe RedLineStealer ext zbetcheckin
2021-09-28 19:02:10http://185.215.113.36/main.exeOffline32 Amadey exe zbetcheckin
2021-09-28 18:07:57http://185.215.113.36/main_signed1.exeOffline Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-12-12 19:29:169c45c5456167f65156faa1313ad8bbaffb8aa375669bf756fe0273580a621494exe CryptBot
2024-11-09 05:17:06cf67a50598ee170e0d8596f4e22f79cf70e1283b013c3e33e36094e1905ba8d9exeAmadey
2024-11-07 06:43:384519ffb96ab3e8a4746518455911475f459685fc4174251a17552f1f100c93b5exe Socks5Systemz
2024-11-05 22:31:13465a1cefe61446110cc521d376651a5074fb87295da5fd64bd74fd25cbab669bexe CryptBot
2024-11-03 21:44:204b81371832a31aa1b9a3f4caf3da072dbadc9793dc92d90ba3ea89c8ba7dd17eexe CryptBot
2024-11-03 20:16:36bf1e76b416fc0342d49fe79da89995717679ad80f8c0dd1a9b591044ef02f0e2exe Socks5Systemz
2024-11-03 10:39:061fc070d52f6c24eb6e83d5e9474d63868d47509a8aea3687782ebf61ebe97cfdexeAdware.Generic
2024-11-03 10:39:052f1aff28961ba0ce85ea0e35b8936bc387f84f459a4a1d63d964ce79e34b8459exe Spambot.Kelihos
2024-11-03 10:35:08bc7d010eb971dbc9cbeedc543f93bb1b6924d57597e213dbe10c2c1efd8d0296exe CoinMiner
2024-11-03 10:34:062f1aff28961ba0ce85ea0e35b8936bc387f84f459a4a1d63d964ce79e34b8459exe Spambot.Kelihos
2024-11-03 10:34:062f1aff28961ba0ce85ea0e35b8936bc387f84f459a4a1d63d964ce79e34b8459exe Spambot.Kelihos
2024-11-03 10:02:138003fd73d5681b78365343e95c96bf7289fbb66ad2e22673099f4ab4e947270fexeCryptBot
2024-11-03 10:02:09e709b26315714057ce041823f8a63f38064790a4a2af8fa00a9b63ea19d82329exeSocks5Systemz
2024-11-03 07:15:1380c8797268cb88f5bef1791ccc88b62288763a27528709886e55175b9bd94487exeCryptBot
2024-11-01 18:00:4380c8797268cb88f5bef1791ccc88b62288763a27528709886e55175b9bd94487exeCryptBot
2024-11-01 17:38:38cf67a50598ee170e0d8596f4e22f79cf70e1283b013c3e33e36094e1905ba8d9exeAmadey
2024-11-01 16:46:170ad7e833d526131900916008913dec998360ee6d1a9aacf3997602e1cfc1c3e3exe CryptBot
2022-01-11 07:37:0431ce6bc633ac2e1e933ca3670c7104222682460055fc354395d4d32b7637dbf4unknown  
2021-09-29 13:15:105f9dfd9557cf3ca96a4c7f190fc598c10f8871b1313112c9aea45dc8443017a2exe  
2021-09-29 10:58:09bcc26c979a4d7b0afec88bdf7c864e965db3041616acea4cda1874ba476e74e0exe 
2021-09-29 10:15:0197fa42e9f36b5e195c9c488df251a607611af5ce878a8f55067fac5de66d9ba2exe 
2021-09-29 09:24:35c5e23e7b15649c2d49b797eba7d7b83c76d661603e1b4bde412185eac2b81982exeRedLineStealer
2021-09-29 06:55:375f9dfd9557cf3ca96a4c7f190fc598c10f8871b1313112c9aea45dc8443017a2exe  
2021-09-28 19:05:059b9b66a158beacb1a23877ab25c70435a43f072f76a0ba35fed9ad32f781d04cexeRedLineStealer
2021-09-28 19:02:10384292cad1c05552ccbd691de48865ce75375f7e601db66b3f5cad0f8f294d6cexeAmadey
2021-09-28 18:07:57ada127dc6a3232b2e9fb8d842c2709ba46b102d683768514ffc9c2eea4fe8492exe