URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.13/inc/crypteda.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3081240
URL: http://185.215.113.13/inc/crypteda.exe
URL Status:Offline
Host: 185.215.113.13
Date added:2024-07-31 17:34:34 UTC
Last online:2024-08-31 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-07-31 22:15:09 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:1 month, 0 days, 16 hours, 36 minutes Bad (down since 2024-08-31 14:51:16 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-19n/aexe d8e81d9e336ef37a37cae212e72b6f4ef915db4b0f2a8df73eb584bd25f21e66Virustotal results 42.47% RedLineStealer
2024-07-31n/aexe e015f535c8a9fab72f2e06863c559108b1a25af90468cb9f80292c3ba2c33f6eVirustotal results 82.19%RedLineStealer