URLhaus Database

You are currently viewing the URLhaus database entry for http://15.204.49.145/files/HAD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2562911
URL: http://15.204.49.145/files/HAD.exe
URL Status:Offline
Host: 15.204.49.145
Date added:2023-03-08 11:33:07 UTC
Last online:2023-04-02 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-03-08 11:34:05 UTC to abuse{at}ovh[dot]net)
Takedown time:24 days, 18 hours, 38 minutes Bad (down since 2023-04-02 06:12:51 UTC)
Tags:exe Socelars

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-11n/aexe b4cda7a0cfad33d6a7202c671dd62a82b050984f5eb93767246cfd31c1b62ebcVirustotal results 21.74% Adware.Generic
2023-03-09n/aexe 6d31a9b4e0edbb5ab718d24b4c096775a1336d144d83ef9a7fc0996ce27d7bf6n/a Socelars
2023-03-08n/aexe 343b71456cdcc0f09baf79a2b0f5befe7043f329899f205699ac3ca2424c8282n/aManusCrypt