URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.11.8/WW/file8.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1478718
URL: http://37.0.11.8/WW/file8.exe
URL Status:Offline
Host: 37.0.11.8
Date added:2021-07-24 18:05:03 UTC
Last online:2021-08-05 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-24 18:06:03 UTC to abuse{at}serverion[dot]com)
Takedown time:12 days, 2 hours, 55 minutes Bad (down since 2021-08-05 21:01:10 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-05n/aexe b4ffe1f2946af70fdfaeac24385c5cbd01a9cf945074e7ba4e1695ad4e00b5d0n/a RedLineStealer
2021-08-05n/aexe 8fdc64fb5d5503b76b30dc4597326f2cc5df69497df35158ba3e11398694732aVirustotal results 43.48%RedLineStealer
2021-08-01n/aexe 3035858921a56999f9c541e51e6bf2c235778b22807f3d1977a261b637e57d8fVirustotal results 30.00% RedLineStealer
2021-07-29n/aexe 54d6f37088e0abbbb462136d7788295afd95c9005cb1a415c05d6e2736e06f6dn/a RedLineStealer
2021-07-29n/aexe 2c4fe0a41b33ce373657bb695cca70b581565273a83ce801c0c4c255b1c1b4b6n/aRedLineStealer
2021-07-29n/aexe 993318d95cf97090412972dd7e5cec57bc6aab81acaf1698390b004bbe1ec4adn/aRedLineStealer
2021-07-28n/aexe d6f3bc6eb1082a7207faa7011913c099d1b007f79df07b5388ae05af91bf80a3Virustotal results 52.86% RedLineStealer
2021-07-24n/aexe 55aecb45a0e3844c0621c28907e857ec0ab23372e57bfa5dd614ea0b298b2c71Virustotal results 39.13%RedLineStealer