URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/szo0xbx8.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338525
URL: http://185.215.113.209/inc/szo0xbx8.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 14:43:12 UTC
Last online:2025-04-18 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 14:44:13 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 9 days, 22 hours, 7 minutes Bad (down since 2025-04-18 12:51:35 UTC)
Tags:185.215.113.16 cryptbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-13szo0xbx8.exeexe 37e633675f5809e9ca90d92d28b35ba2fcc807cc2f0be1fc655a98df06a30845n/a 
2025-03-15n/aexe 9c11e1239290d287b46e3f50988106427fca1054d30c975cf39a3b68c23aa21dVirustotal results 7.14% 
2025-03-14n/aexe df78dd285f16b5e628e07d7db297146e2cdac7767629eb9278cc2f070bd2bfeen/a 
2025-03-14n/aexe 36c2f2baf520c1c5ed4e612c97a09e8971e9be4cf1da15acd7ce29048e11dde7n/a 
2025-01-25n/aexe 8f02b43a5c8c62b0651d4b04276ba142b479da60a902dde8b2d75e983596480fn/a 
2025-01-25n/aexe d59e405f20fe2a80a0fb4d694a25feafb65212c3bcddcb42737fa164784aaffcn/a 
2025-01-24n/aexe 0c5f4c32f56a7c489f2456c317160234c16e14d2a8f36b6beda80bffcaad0d31n/a 
2024-12-09n/aexe 4775ea475df3798d292243807fe77d734d95bf82d42bcd4a9a66fef1385a6b41Virustotal results 69.44%CryptBot