URLhaus Database

You are currently viewing the URLhaus database entry for http://181.223.9.36:9000/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3610038
URL: http://181.223.9.36:9000/file.exe
URL Status:flame Online (spreading malware for 7 months, 13 days, 15 hours, 29 minutes)
Host: 181.223.9.36
Date added:2025-08-23 12:14:19 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-23 12:15:15 UTC to abuse{at}netservicos[dot]com[dot]br,abuse{at}vivax[dot]com[dot]br,virtua{at}virtua[dot]com[dot]br,abuse{at}claro[dot]com[dot]br,contatoregistro{at}claro[dot]com[dot]br,suporterede{at}claro[dot]com[dot]br)
Tags:Sliver ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-03file.exeexe 76fdc0fc53758a6e00019df7c9d034de03fc6a22252ba2ed94cb9758de851041n/a 
2025-12-21file.exeexe 9235031b0a1bf49f84a6d9337e239b21c4c31d8ffbaa07e09063caf22d0a09dbn/a Sliver
2025-09-20file.exeexe 9c28f5ed474b49083d5ecc0259d87379101e90ad12f1372b754a115cfe5694a3Virustotal results 75.00% Sliver
2025-08-23file.exeexe cd3718dc391f982c7843289221ca30666be93007a4e7ba0b9d5a6b69f25cefd7Virustotal results 60.56%Sliver