URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/v_dolg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338511
URL: http://185.215.113.209/inc/v_dolg.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 14:42:55 UTC
Last online:2025-04-28 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 14:43:15 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 19 days, 23 hours, 19 minutes Bad (down since 2025-04-28 14:02:42 UTC)
Tags:185.215.113.16 LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-06v_dolg.exeexe abbc78c16dc3ab442516dc515aa0225ef14107faf03d10b691850532c219f2den/a
2025-03-14n/aexe 163f81f8358c6d1ea20934dfe28b29219d0d600cbec412e0791a52f7f983833cn/a 
2025-02-28n/aexe 3906274a409b2a317c868c0f84d6434af19e3405c000331661a6875cebb4e379n/a 
2024-12-09n/aexe df6e6d5bead4aa34f8e0dd325400a5829265b0f615cd1da48d155cc30b89ad6dVirustotal results 30.99% LummaStealer