URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.16/inc/build2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3071940
URL: http://185.215.113.16/inc/build2.exe
URL Status:Offline
Host: 185.215.113.16
Date added:2024-07-26 17:57:09 UTC
Last online:2025-04-28 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-26 17:58:06 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:9 months, 5 days, 19 hours, 49 minutes Bad (down since 2025-04-28 13:47:47 UTC)
Tags:DeerStealer exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-15n/aexe 81944f97fc8bd27fff19ba80a4cc27cc639e9708c46768bceaeb6bf1e9ed8bc9Virustotal results 30.14% 
2025-03-14n/aexe 33eb8011903501a96fe0bc2a49306fc35cfc44a4e63232744fe8d4d383c89b23n/a 
2025-01-25n/aexe 6e0abbe3847fdead4a751757589922cfe132f708a7c2b6d5421060c826b5f916n/a 
2024-07-26n/aexe 67ce38dec54fd963ff28f4a257d58133eb241c909f9e06c859de0a7f00976202Virustotal results 21.92%