URLhaus Database

You are currently viewing the URLhaus database entry for http://181.223.9.36:9000/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3610038
URL: http://181.223.9.36:9000/file.exe
URL Status:Offline
Host: 181.223.9.36
Date added:2025-08-23 12:14:19 UTC
Last online:2025-12-11 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-23 12:15:15 UTC to abuse{at}netservicos[dot]com[dot]br,abuse{at}vivax[dot]com[dot]br,virtua{at}virtua[dot]com[dot]br,abuse{at}claro[dot]com[dot]br,contatoregistro{at}claro[dot]com[dot]br,suporterede{at}claro[dot]com[dot]br)
Takedown time:3 months, 19 days, 18 hours, 32 minutes Bad (down since 2025-12-11 06:47:58 UTC)
Tags:Sliver ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-20file.exeexe 9c28f5ed474b49083d5ecc0259d87379101e90ad12f1372b754a115cfe5694a3Virustotal results 75.00% Sliver
2025-08-23file.exeexe cd3718dc391f982c7843289221ca30666be93007a4e7ba0b9d5a6b69f25cefd7Virustotal results 60.56%Sliver