URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/worker.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338125
URL: http://185.215.113.209/inc/worker.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:17:53 UTC
Last online:2025-04-28 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:18:12 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 20 days, 3 hours, 5 minutes Bad (down since 2025-04-28 11:23:18 UTC)
Tags:185.215.113.16

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-05worker.exeexe e42c68111ac06a2c6b11e53e950320000f923e6c4259788b834fb20ad7563b66n/a 
2025-04-01n/aexe 25e6db6c37e8d6efdf1cf6a10d0e917ae7c2756ec36d86ed2350546944ec9957n/a 
2025-03-15n/aexe 03add43d70dbb3a221f90c4f74e0212bb5fc5d1972ef96ccb8b7f2ea0fcb11c6n/a 
2025-03-14n/aexe f4419c212c091133f0433c72157307a201e2d2cfbc590b1d0851068149a3685fn/a 
2025-02-27n/aexe 98b9d263909026f73a74d2ac60d943ba1d3717166d445daaef884c8ded525c26n/a
2025-01-27n/aexe c44bf9034f69c865fd5c5aa5ee8994917e15ffc66ac2bc5d8b617ba442ba1f71n/a 
2025-01-26n/aexe 81ef0d1969610bb92246723b3d35a25d861bc9c3386261e31a9ac2f5f59b9314n/a 
2025-01-26n/aexe ae6a9691e4422470b473df2e0130dced5217bcf9ed87fbb2a6e5de35c0d75df4n/a 
2025-01-25n/aexe 941bacb9e41d77002d15a5ac5980f387f9de76ae3f78deff1732659f7d17cc8bn/a 
2025-01-24n/aexe a0546960f35dc409b6fc50e0bfad57bad004446558ff0778929831c3119658dbn/a 
2025-01-23n/aexe 817d894ecb03f5845c6d38af768e2493982419113f153f1c26e15be733229b85n/a 
2025-01-18n/aexe a548dfe5e271c59598ce4e8c91c0767199a98c1987e5304f92c72250e862e77cn/a 
2025-01-11n/aexe 3b00c0f605bcaca69ac01ae2c543f7a508d1506a26ea19c3d3cf36ec6e162503n/a 
2024-12-15n/aexe e14a4497948ff1113e7d10e8cd4f385f4340ecb11db8f5ad3d0cb2a7f34f7f40n/a
2024-12-09n/aexe d5008a50f2867a9ec72e557977f54f9867b861dd184149016e98c4ee0b02806aVirustotal results 64.18%