URLhaus Database

You are currently viewing the URLhaus database entry for http://194.61.120.8/g63.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1372355
URL: http://194.61.120.8/g63.exe
URL Status:Offline
Host: 194.61.120.8
Date added:2021-06-17 08:12:04 UTC
Last online:2021-06-18 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: benkow_
Abuse complaint sent (?): Yes (2021-06-17 08:13:03 UTC to abuse{at}intersect[dot]host)
Takedown time:21 hours, 50 minutes Good (down since 2021-06-18 06:03:41 UTC)
Tags:exe RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-17n/aexe a6c43747a61dbbfcabd23c6595f9237950dafddf54b187c6300ec75340f2d6d9n/aRedLineStealer
2021-06-17n/aexe bae92310790c73871ab664dea8962cecc2bf2785c768196b04731bf8a7f45399n/aRedLineStealer
2021-06-17n/aexe c1f32a2cb465e9587dd6dce2471093bea658681eeb66f573acfa54fd28e769d7n/aRedLineStealer
2021-06-17n/aexe 857b888bb465ce55999892cc1deaa9fdacc767b9b69439c266acce7a05e8ce47n/aRedLineStealer
2021-06-17n/aexe 388f560247550b704f82215f4b84d90319442ca1f5052346403fb1a723f2b920n/aRedLineStealer
2021-06-17n/aexe 2fbe77c5b7f1eebb7dc61c48066be89952634691b8a3a23b90c59a19848cd42bn/aRedLineStealer
2021-06-17n/aexe d425af4cb24c185849ec0c68748a7cfe455e97f44bf125bbeca94b250c0778ddn/aRedLineStealer
2021-06-17n/aexe ed10575d466f50c9ad8b7e59c614c6e6e57206820646ec7eab24e512f588ee73n/aRedLineStealer
2021-06-17n/aexe b9b172003da4364527e6fd11d03ef5ae1e503a3fb92b16f2261284746960844en/aRedLineStealer
2021-06-17n/aexe 0d5c3f624b4b07fbf3720815913d7c4aaa5bae13b004cb28b8cadad519ce726dVirustotal results 33.33%RedLineStealer