URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/Client_protected.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338126
URL: http://185.215.113.209/inc/Client_protected.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:17:58 UTC
Last online:2025-04-28 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:18:12 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 20 days, 2 hours, 24 minutes Bad (down since 2025-04-28 10:42:39 UTC)
Tags:185.215.113.16 njRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-14n/aexe 6244488656ec0c812b4c2f00434a3a1a88f75b268503c62461975f994847424cn/a 
2025-02-28n/aexe 36dd1fc32cade3e70684c40e1aff8edc1bb9927646dc9c4e9cf198d2d36e1b8an/a 
2025-01-24n/aexe 78062803e6d3d0416f7b85100736b02cca58856fbf50e094f6ad6a6638a1b5bdn/a 
2024-12-14n/aexe 963c92f16d53d94190bb968bf9fed88016da172138b2afe3aba1da6d801d2b7en/a
2024-12-10n/aexe 5b5185d631b63cbf3ec8999d66525785941a72a24d4e6de2d4c06c0634715c31n/a 
2024-12-09n/aexe df606ef08b80c10d12a7372505f51e2641b263ded0280edcaf9085e7419b5f3eVirustotal results 82.19%njrat