URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.103/test/do.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3182944
URL: http://185.215.113.103/test/do.ps1
URL Status:Offline
Host: 185.215.113.103
Date added:2024-09-20 14:33:07 UTC
Last online:2024-10-18 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-09-20 14:34:11 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:28 days, 4 hours, 56 minutes Bad (down since 2024-10-18 19:30:34 UTC)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-12n/atxt 233dc91536e57adbb2153512f56f098db701e43a7768508c9e9f290c952f1319n/a 
2024-10-11n/atxt 1915177e6c6f0a3ef26d7a2bcbee8d1d26a5fdc9d0afd26c671c41f99b352970n/a 
2024-09-28n/atxt 0244c352cc327e77ae9b2cbc1508efa29e3a741e8a50369cc82090a3b47a7c5bVirustotal results 0.00% 
2024-09-22n/atxt bd90bea09b603b65d008571e1df5dfbe65ba3a587083e3d059a7d061010751feVirustotal results 0.00% 
2024-09-21n/atxt b4712fcf854df4f6a8fc1a87c7f2910bfc2890496d16f561d92af1438caffd72Virustotal results 0.00% 
2024-09-21n/atxt f5f6fe589d44294495e0d811b82c206d1bdf823750a20c75d21e0b3183c3322fVirustotal results 0.00% 
2024-09-20n/atxt 717c09427fa5754ba92f92961545534048d0a76528c2e95c4d5ec6cef47c612fVirustotal results 0.00%