URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.16/inc/dccrypt.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3068351
URL: http://185.215.113.16/inc/dccrypt.exe
URL Status:Offline
Host: 185.215.113.16
Date added:2024-07-26 09:25:09 UTC
Last online:2025-04-28 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-26 09:26:07 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:9 months, 6 days, 1 hours, 51 minutes Bad (down since 2025-04-28 11:18:01 UTC)
Tags:exe PureLogStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-30n/aexe 422437592e3f005cc86436ae89d3724fafca9c7fe098ab3c48b65cecdf1e0c72n/a 
2025-03-14n/aexe 30295fe8cbdd0fc86393fc4033dd58d2d2c03dad4c23a1a780ed2e0d17871d2en/a 
2025-02-28n/aexe 5516894b0b3ebf01afb8b8ad07860807482635adb1a0f0123592fa29169d651dn/a 
2025-01-25n/aexe 4c1914ecc304dfde58532208dd3daa2c26b5cd23bf58cac3987942668047c4b5n/a 
2025-01-25n/aexe 7c15e5cef438c2ddcb908725b68e74fc6aa95f0d8e5b8d73b3e3b2cb94b1261en/a 
2024-07-26n/aexe e91ebc7e19b4dec3ce6f2aaf4ee8fb9fb24cba265088781f9845d8a32d1f2948n/aPureLogStealer