URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.201/WW/file5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1453955
URL: http://136.144.41.201/WW/file5.exe
URL Status:Offline
Host: 136.144.41.201
Date added:2021-07-14 14:21:04 UTC
Last online:2021-07-24 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-14 15:24:27 UTC to abuse{at}serverion[dot]com)
Takedown time:9 days, 16 hours, 36 minutes Bad (down since 2021-07-24 08:01:26 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-22n/aexe 1755700dca35f231e22781a85fe5ac3b611c9db2aa79b451224b48ea62945fc6n/a RedLineStealer
2021-07-21n/aexe fd485101ff27d3381e9356c770b38aa1453e96c43fa3eb71dc7b790b6fe9d1efVirustotal results 30.00% RedLineStealer
2021-07-19n/aexe 8e7121b812c07d5fb5dda8e5f8a8d0529d87d6f6332f0509758fc8e79c643d01Virustotal results 45.59% RedLineStealer
2021-07-16n/aexe 349d4a44c8f68f89aedf97b1fb081433dfee27215e4c16ae3bef4915a99d6d62Virustotal results 7.25% RedLineStealer
2021-07-14n/aexe 416a5680b7a1bb7ade8ed80b8002ee97e801a98aef49f3dc214d5acbdda14819n/aRedLineStealer