URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.16/inc/szo0xbx8.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338590
URL: http://185.215.113.16/inc/szo0xbx8.exe
URL Status:Offline
Host: 185.215.113.16
Date added:2024-12-09 14:44:47 UTC
Last online:2025-04-28 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 14:45:28 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 19 days, 21 hours, 26 minutes Bad (down since 2025-04-28 12:11:54 UTC)
Tags:cryptbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-13szo0xbx8.exeexe 3fabff1999b95a385ca072d6465ee9273744e4054be797a4dfc6309acea37b58n/a 
2025-03-27n/aexe 86b5faf1d377671662735c5dd4a20e30ecab4de685b398b29e2d312bc4c0e3d1n/a 
2025-03-15n/aexe df78dd285f16b5e628e07d7db297146e2cdac7767629eb9278cc2f070bd2bfeeVirustotal results 9.59% 
2025-03-14n/aexe 9c11e1239290d287b46e3f50988106427fca1054d30c975cf39a3b68c23aa21dn/a 
2024-12-09n/aexe 4775ea475df3798d292243807fe77d734d95bf82d42bcd4a9a66fef1385a6b41Virustotal results 69.44%CryptBot