URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.19/inc/clcs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3117561
URL: http://185.215.113.19/inc/clcs.exe
URL Status:Offline
Host: 185.215.113.19
Date added:2024-08-20 12:45:41 UTC
Last online:2024-10-25 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-08-20 12:46:08 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:2 months, 6 days, 6 hours, 39 minutes Bad (down since 2024-10-25 19:25:09 UTC)
Tags:cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe 3a6dd829c92cd14debd5e27e3943e990458bc1d7683542768c33250d4f9edc92n/a 
2024-09-28n/aexe 9c928ac1c6b150980e368030289d99dde524aaac9a5db28a5fcba691ceb4bd70n/a 
2024-08-23n/aexe b714de61da42434729bb5e5c9d6885b0de2f2036bf685049ad65cf4f2949c37cn/a CryptBot
2024-08-22n/aexe 29036a1125ac5f5b8a4bfb794fa965efd1f5e24853db3fa901b17d96ba901ca8Virustotal results 40.54% CryptBot
2024-08-21n/aexe b78c67f56b7af5533a502fef2ed9b0ce4c9d507214a74f7d0501611941197b75Virustotal results 13.33% 
2024-08-20n/aexe e6e749bae0e92e8325a68dc2bf3c9f8a6c51a67b16ab0328758d254cb7d21f12Virustotal results 36.00% CryptBot
2024-08-20n/aexe 95b45abfc66f31f500af4b03aa645bdf71e64bcbe52d1003a58e947e9f863bacVirustotal results 39.19% CryptBot