URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.8/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3552537
URL: http://185.156.72.8/1.exe
URL Status:Offline
Host: 185.156.72.8
Date added:2025-05-26 00:09:06 UTC
Last online:2025-07-02 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-05-26 00:10:08 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:1 month, 7 days, 17 hours, 7 minutes Bad (down since 2025-07-02 17:17:20 UTC)
Tags:c2-monitor-auto dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-261.exeexe 8f4a8ab0543c2897b50fed3345b850e6aa309671053bfab327b532c63322e811Virustotal results 53.52% 
2025-06-181.exeexe 64d07657ad5aabe58ebf4a08202f5395562b805d370898d50eee43d334167b84n/aDiamotrixClipper
2025-06-131.exeexe f88c1e227e3a959aa8609eae1a6ec68ba088ad9b261b99f6b91fa6deb796dd15Virustotal results 47.17% 
2025-06-061.exeexe 5abfabe996507cb7d863a9bb8e3573dc89ca5d0db276dfa4f26fed4f12236653n/a 
2025-05-291.exeexe c8913dafd7358b2d266c485d26f80835380468e00316f015dbe54c42eb812d74Virustotal results 73.24%
2025-05-271.exeexe d325b330fe005578a64d1e593917e9d757ce4614d0d75d26545b5ebd8f626d02n/a
2025-05-261.exeexe 5b9d368a0a91ebed24e3acabffa639916f4661474156c2dd298d8ea7dda81110Virustotal results 28.17%