URLhaus Database

You are currently viewing the URLhaus database entry for http://15.204.49.142/files/New1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2567385
URL: http://15.204.49.142/files/New1.exe
URL Status:Offline
Host: 15.204.49.142
Date added:2023-03-12 12:33:13 UTC
Last online:2023-03-21 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-03-12 12:34:05 UTC to abuse{at}ovh[dot]net)
Takedown time:8 days, 18 hours, 8 minutes Bad (down since 2023-03-21 06:42:20 UTC)
Tags:dropped-by-PrivateLoader LgoogLoader Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-15n/aexe 19180f2ad7a48d765ee7f5149f3f278b5343ea9f49ec82df9ba4544824189f9dn/aAdware.Generic
2023-03-14n/aexe 60c8df7b74c3e6c38a6162af6fe798cf1f291e661609af346ee2b146de78158dn/aRhadamanthys
2023-03-12n/aexe 28bb20329cf6024057a4834e899520a55dcc7bb6b22ad783069ab2d1e2124e82Virustotal results 31.34%Rhadamanthys
2023-03-12n/aexe 8a7eadc7085b0a572fe4cfe17a02e828107d2f3dc0e1e2730a47fa1bed43e349Virustotal results 35.82%Rhadamanthys