URLhaus Database

You are currently viewing the URLhaus database entry for http://15.204.38.209/files/File300un.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2761437
URL: http://15.204.38.209/files/File300un.exe
URL Status:Offline
Host: 15.204.38.209
Date added:2024-02-15 04:01:09 UTC
Last online:2024-03-11 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-02-15 04:02:06 UTC to abuse{at}ovh[dot]net)
Takedown time:25 days, 16 hours, 0 minutes Bad (down since 2024-03-11 20:02:22 UTC)
Tags:dropped-by-SmokeLoader LgoogLoader Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-11n/aexe 483445b34f7a909195d618c996721cf004e26e2e795ad0c7d8fd026d6efe0508n/a 
2024-03-09n/aexe ba2a72ae0028cd079eaa6151df80692506d3569e94cc24d8a2be5a5f3aa9dd55n/a 
2024-03-08n/aexe 39245735a6a4d2495cb6a5207bb9d5e2b6c058d113b6b0efc292330a89611757n/a 
2024-03-07n/aexe afc1a5c5216b9c029a65d3fbdfa08bb351d9852143537955a2303ece3657f712n/a 
2024-02-17n/aexe eb76472cb7a072bbfb59918ef1594ca866fbd9884b2776cb5e427dcec2d3b13en/a Stealc
2024-02-16n/aexe a020ef28937a1415b7f901865288f6c080a7dca39bc0428e2145cd99e8ad8168n/a Stealc
2024-02-16n/aexe 32497449b0fce1023154fd322093211786e5c20b8d09ec799303e516966eaa26n/a 
2024-02-15n/aexe fa776a4e5e0653f7856a19c3a9fbdad306eb9365cb553bc223d8075be5f5cd3bn/aLgoogLoader