URLhaus Database

You are currently viewing the URLhaus database entry for http://176.113.115.149/svc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3423150
URL: http://176.113.115.149/svc.exe
URL Status:Offline
Host: 176.113.115.149
Date added:2025-02-01 15:23:06 UTC
Last online:2025-03-03 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-02-01 15:24:06 UTC to abuse{at}starcrecium[dot]com)
Takedown time:1 month, 0 days, 2 hours, 42 minutes Bad (down since 2025-03-03 18:06:33 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-02n/aexe 7745299401a69500f52e7fcce6e7c4e6037455f89dbebae1802d983c1bd326f6n/a SVCStealer
2025-02-28n/aexe 8632d66c50135cca25705fdbe768902e283f61e08621fcd1a0cdc12277984e27n/a SVCStealer
2025-02-27n/aexe 1a5da09e281f4a2acadf791cbad426351a769d2b8057005b1415e74a7ddfb0afn/aSVCStealer
2025-02-21n/aexe ceafe9f00acad349984509dbf2af9749a9d62ace62d87cc290b2eaa85f629a34n/a 
2025-02-14n/aexe 5400f3387d683cd31ed39f493893da4107b65be55163573bd219c749802afe69Virustotal results 51.39% SVCStealer
2025-02-08n/aexe da8cbf6c2b20389be881bb0c84a74d8a84c525df491f44f883b424075f9391ben/a SVCStealer
2025-02-07n/aexe 4254de273cf58a956855203549ce4c6ffa2e0eba107d4a11e884f4ea064821d5Virustotal results 50.00%SVCStealer
2025-02-06n/aexe b1e889002d9174c58dd9d8b20758516a3ff6e636ff14e00793da3ff9a09a7e9eVirustotal results 64.79%SVCStealer
2025-02-01n/aexe 9f77bbcdd38b75f6ec62bc84ff8adcf7be6c9c184a61941af75a2b8f93091fb8Virustotal results 60.34%SVCStealer