URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/Setup2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338135
URL: http://185.215.113.209/inc/Setup2.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 08:19:05 UTC
Last online:2025-04-18 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 08:20:22 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 10 days, 4 hours, 37 minutes Bad (down since 2025-04-18 12:57:27 UTC)
Tags:185.215.113.16 cryptbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-15n/aexe cafca8cd9fe61429eb2300251afb5e18306ebaf51c35a05df4af4bd9b841591dn/a 
2025-02-17n/aexe 1f6ff799a6957ffc5d615ff63cceecc20ead320bd5bec5920abef3d7fa04b61an/a 
2025-01-20n/aexe c433d4c5e70ed8db9884dbac9084d901ae3ec1d4daa5e38fa04309a117ddbdabn/a 
2025-01-16n/aexe 0e8c4a00626fcb991b6c33cdeeb0307610237ea2899c6819c65792d3e0632911n/a 
2024-12-09n/aexe 9afd9e70b6f166cfc6de30e206dff5963073a6faeff5bcc93ee131df79894fc2Virustotal results 76.06% CryptBot