URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/needmoney.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3337955
URL: http://185.215.113.209/inc/needmoney.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:13:13 UTC
Last online:2025-04-28 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:14:13 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 20 days, 3 hours, 40 minutes Bad (down since 2025-04-28 11:55:09 UTC)
Tags:185.215.113.16 Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-06needmoney.exeexe 4c7a99c94a152522d1f2ae4fc197fa01826dadb0ce886abc4bbb28a0785ee148n/a
2025-03-14n/aexe 049be0d448259868ffe190da03c1574623b9d17d0ff2c980a0b71de7d8ba088cn/a 
2025-01-25n/aexe 44f04993b1e8d333c5bfef107d5649c9b90e983d1e430fc6ef0c22dbbf2d87a7n/a 
2025-01-25n/aexe 7ba778c7b6f06d73a3067fff8f09aba8ec08f5a89c0b9d2b0be74dbd93cabe01n/a 
2025-01-25n/aexe 4c339e966e8205b89503d59101603270a05efefb4219983fe8a73802cda53253n/a 
2025-01-24n/aexe f1908f5e326f3e241c2a28697ff0c48ba0faf45200dfa1d5c20dc99a689f19abn/a 
2025-01-20n/aexe 77d5652ad12101ef9fa8c568c9ac406bcafb4bebe20e9b5f572bcf1391257c47n/a 
2024-12-09n/aexe fd3edfaff77dd969e3e0d086495e4c742d00e111df9f935ed61dfba8392584b2Virustotal results 83.33%Stealc