URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/shopfree.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338059
URL: http://185.215.113.209/inc/shopfree.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:16:01 UTC
Last online:2025-04-28 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:16:19 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 20 days, 3 hours, 7 minutes Bad (down since 2025-04-28 11:24:16 UTC)
Tags:185.215.113.16 LummaStealer Sliver

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-14n/aexe be84cc0401820eae039e2d9adeb867687b11b3641a6e2d730222fb8448f359ddn/a 
2025-02-28n/aexe 01151dbf8918082e42f8b8b00df007e4ea3617689b851cd9298cc8c5b6b76e56n/a 
2025-01-25n/aexe 63426f8e0e7f8665d53456fea87bc12761287327e88677c48d27aa86dd8dbc2dn/a 
2025-01-20n/aexe cd384cfda26bc6e0f431b4b72ef52cdb97365fcb10c9b9e45634724fad0c6956n/a 
2024-12-10n/aexe 4cb6e157f0e9238f03c72cc399d9178e997f97c1c80360b6cd3278af5ece1a15n/aSliver
2024-12-09n/aexe d76391b6dca2b5057a0adfb446cf6f80e9be5ec4241cfeddff6e1ca03b331a72Virustotal results 71.83%LummaStealer