URLhaus Database

You are currently viewing the URLhaus database entry for http://193.135.12.27/g63.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1377666
URL: http://193.135.12.27/g63.exe
URL Status:Offline
Host: 193.135.12.27
Date added:2021-06-18 23:30:05 UTC
Last online:2021-06-19 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-18 23:31:02 UTC to abuse{at}intersect[dot]host)
Takedown time:10 hours, 14 minutes Good (down since 2021-06-19 09:45:17 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-19n/aexe 1e7c89c70a2ec6c77feb2dd9a21809c7b5eecc070705ba999c2b6392277f8ee4n/aRedLineStealer
2021-06-19n/aexe 4cf4fe7855632a62537bf2acaa36cc8341cc9166370f12afab068b32d17a1c33n/aRedLineStealer
2021-06-19n/aexe ff7e438650ddbcf67f1625ca8b7de515923a552236903af2ba27448427726688n/aRedLineStealer
2021-06-19n/aexe d9161a1a9dda00926bc9c6207f1629342db35543405ac562d3f749d5d717aa63n/aRedLineStealer
2021-06-19n/aexe c9a73eade294a277e1120bc6107a13b640ba797f09d3edfa3992577a46275ea0n/aRedLineStealer
2021-06-19n/aexe 89a33850501752a857fcd4dcf572ab38be1d61c07273d2c2cb546a84b02a318en/aRedLineStealer
2021-06-19n/aexe 397ed238fbdca9e09a2429f2249c62606a1431f1d99995dcd709b13428318bfen/aRedLineStealer
2021-06-19n/aexe 34c3d185dc61472fccfc4b49d646ccca9d057596dc8947e62773ca63205ef67bn/aRedLineStealer
2021-06-19n/aexe b6ddaf7b356ff21ae461672f44f87944e5b5879b7442d50b545909a6fdc0e180n/aRedLineStealer
2021-06-19n/aexe bdbff3e390c1994aa66169922985f28a2b5a647ec1af964cdc135286aed800a0n/aRedLineStealer
2021-06-19n/aexe 38be3ad05a6c425c48e00b37c6c98b2c8deba6f0183c87e512416f9c8e5f6434n/aRedLineStealer
2021-06-19n/aexe c5de348127af86dbf2095c989af056f0e7949a9b4102f9473be31a386376def0n/aRedLineStealer
2021-06-19n/aexe d890825bd897e91e523f985a64b2f624108433a257e8bfb141f5a95492ff4497n/aRedLineStealer
2021-06-18n/aexe af9417afddd1867732538ff369e917f68407906bef20dfb2e0b99ee8a04664ccVirustotal results 39.13%RedLineStealer