URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/roblox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3352182
URL: http://185.215.113.209/inc/roblox.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-16 14:26:18 UTC
Last online:2025-04-28 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-16 14:27:13 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 12 days, 21 hours, 22 minutes Bad (down since 2025-04-28 11:50:11 UTC)
Tags:185.215.113.16 185.215.113.209 PythonStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-15roblox.exeexe 38162a01f4fd7f18ac7436c73fb1fcd4271cababf4fa1a4c7887dde77ac01972n/a PythonStealer
2025-03-14n/aexe b5e07da2745395df01cc3d988693a3629fa0d41c211e741d69ec79f5416c8098n/a 
2025-01-28n/aexe fe4e4061870dd3f050958fd72284f88ec02809a5d7bf6219babf934f468fa14an/a 
2025-01-26n/aexe ff680962ef11da508ae2f2288ebe3d79dace807401d0ea53588a013f4a10053cn/a 
2025-01-25n/aexe 4aad818426253447d608094a5dab2fa27accf2ccf3cc9060071fbcb87bee5c31n/a 
2024-12-31n/aexe 4ef47a97b89cd6313d481b7d29c0962bf6c13afcf0c073416638aed6b69a49ddn/a 
2024-12-16n/aexe bcdd8b7c9ec736765d4596332c0fec1334b035d4456df1ec25b569f9b6431a23Virustotal results 44.44% PythonStealer