URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/l4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3346526
URL: http://185.215.113.209/inc/l4.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-12 15:34:11 UTC
Last online:2025-04-28 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-12 15:35:21 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 16 days, 21 hours, 32 minutes Bad (down since 2025-04-28 13:08:08 UTC)
Tags:PythonStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-14n/aexe 290f66eedbe601ed4b4f6ba6c5820345603b97b6dd733ea84f4f3c43a5a720a3n/a PythonStealer
2025-02-10n/aexe acc786f0aecfdf4d88bb0d32967391ebef75a9c10d73476d41b8398bd2cf38efn/a PythonStealer
2025-01-27n/aexe db2c0bf17c99e6d74dbe813a3d9cd9946e408b561109c316cc9049bb228d03b7n/a PythonStealer
2025-01-24n/aexe f6267287efd3e9b52153c944e37e816cc6d6476797ba6662db91edc9d84a3340n/a PythonStealer
2024-12-12n/aexe aa50c900e210abb6be7d2420d9d5ae34c66818e0491aabd141421d175211fed6Virustotal results 62.50% PythonStealer