URLhaus Database

You are currently viewing the URLhaus database entry for http://15.204.49.145/files/New1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2561815
URL: http://15.204.49.145/files/New1.exe
URL Status:Offline
Host: 15.204.49.145
Date added:2023-03-07 15:24:19 UTC
Last online:2023-04-02 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-03-07 15:25:12 UTC to abuse{at}ovh[dot]net)
Takedown time:25 days, 14 hours, 37 minutes Bad (down since 2023-04-02 06:02:21 UTC)
Tags:dropped-by-PrivateLoader LgoogLoader Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-11n/aexe 8a7eadc7085b0a572fe4cfe17a02e828107d2f3dc0e1e2730a47fa1bed43e349Virustotal results 23.53%Rhadamanthys
2023-03-09n/aexe 4e206df50e3327418c6c9078b720d5faac9b3bac31998e29d1091fc2fd2418bbn/aAdware.Generic
2023-03-08n/aexe 4eeeb2fb37c066baa19b53a02d93d82c40fbedbda7610720b8733c6c1aab555bn/aManusCrypt
2023-03-07n/aexe 3c41412eb5d424cbf29a62862bc2ccc0ba89c32c27e36f5c74a8d16a82fe2331Virustotal results 46.27%Rhadamanthys