URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.19/inc/crypteda.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3067437
URL: http://185.215.113.19/inc/crypteda.exe
URL Status:Offline
Host: 185.215.113.19
Date added:2024-07-25 23:14:12 UTC
Last online:2024-10-25 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-07-25 23:15:10 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:3 months, 1 days, 19 hours, 32 minutes Bad (down since 2024-10-25 18:47:17 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-12n/aexe 5a4308d45dc245870376ece2209450e5ca46872e632c81c3c61178f139ef223dVirustotal results 56.76%RedLineStealer
2024-08-19n/aexe d8e81d9e336ef37a37cae212e72b6f4ef915db4b0f2a8df73eb584bd25f21e66n/a RedLineStealer
2024-07-25n/aexe e015f535c8a9fab72f2e06863c559108b1a25af90468cb9f80292c3ba2c33f6eVirustotal results 49.33%RedLineStealer