URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/BattleGermany.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3337872
URL: http://185.215.113.209/inc/BattleGermany.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:10:05 UTC
Last online:2025-04-28 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:10:20 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 20 days, 4 hours, 40 minutes Bad (down since 2025-04-28 12:50:46 UTC)
Tags:185.215.113.16 RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-15n/aexe 572313c90f3577b937802f24ba2ef66bd058e1e9e8fc27fcfc79f420af672305n/a 
2025-03-14n/aexe 2fe76c224e2fbf3c52946e9d77e454d5e8ca29baf3d7264443d9f378a669a412n/a 
2025-02-28n/aexe 5506c044c98882e61f32ba2688118c6c753adf09aa13e92ffbb1790b1a05c6acn/a RedLineStealer
2025-02-28n/aexe e2a14c2fb2b00f1bd8ffb077bc5c359206d22180fa68be755ba62406dc5568d7n/a RedLineStealer
2025-02-26n/aexe eb53f7bb5abcbf85b9f1a603f6ef0a52083965bd2c7c3c9dfcff6b02aa53b7cen/a 
2025-01-20n/aexe 4c320c99fac583f8c1e48ac12112bd4b0ba22613cb24b2fba6785e97adee5f63n/a RedLineStealer
2024-12-09n/aexe 7636d2367079eabd9da2bb40935df3da580affc47473fd93ed3b2e01ee6c46e5Virustotal results 76.81% RedLineStealer