URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.26/JavUmar1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3234276
URL: http://185.215.113.26/JavUmar1.exe
URL Status:Offline
Host: 185.215.113.26
Date added:2024-10-14 07:14:10 UTC
Last online:2024-10-25 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-14 07:15:15 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:11 days, 10 hours, 29 minutes Bad (down since 2024-10-25 17:45:14 UTC)
Tags:cryptbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-23n/aexe 2b1f016f12fef7124ea7c9898622e650e53814f2d5ff4d76fa712c3e591f9a7fn/aCryptBot
2024-10-22n/aexe 742bc854b92d5379dd8ca717e798adfe84d864b9eaabf83c7bf9b7fb92814e1fn/a 
2024-10-21n/aexe e1475c8d8760880e5d874a7bacb983cedda7691e507f7b1f89269333063239ccVirustotal results 21.92%CryptBot
2024-10-20n/aexe 6798b30915ded323d8ca7f310a7d518cfa5de39bcc20ae984c9a3b65ccbeb941Virustotal results 34.25%CryptBot
2024-10-20n/aexe 992bd4bb6280e1d946ce2a65c5ee6c620b3074a3195c96595f3396ce33369922Virustotal results 35.62%CryptBot
2024-10-18n/aexe 8ad7c506b6c146384ab9b6effd12c9bd586518100e35c4fcb4744b40d10bf25aVirustotal results 34.72%CryptBot
2024-10-16n/aexe 4caa926d2422c584f16a4373daea24880fbd08a7baf3c9214421281965f89ec6Virustotal results 34.25%CryptBot
2024-10-15n/aexe dc26f099c5875a25fab9ed9bf97c941e6e8bb61dcbc67897c2b758e30ad265a3n/aCryptBot
2024-10-14n/aexe abc53ac9f7564ceba0a7548b880b1e92c8e0329ff9680e3c5f06abcbd4e869b9n/aCryptBot