URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.11.8/WW/P4GlorySetp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1478887
URL: http://37.0.11.8/WW/P4GlorySetp.exe
URL Status:Offline
Host: 37.0.11.8
Date added:2021-07-24 19:38:03 UTC
Last online:2021-08-01 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-24 19:39:02 UTC to abuse{at}serverion[dot]com)
Takedown time:7 days, 8 hours, 15 minutes Bad (down since 2021-08-01 03:54:11 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-31n/aexe bb0aa423e1c6083ea66b79d36c3efc7b5ecd6a1ef10444fbc85cdd57eb57ca55Virustotal results 30.88% RedLineStealer
2021-07-29n/aexe a0eefda8f35e212d879a3fc5960d5dce7bdd04528b3177e979d98f2ef8e3b0a3Virustotal results 30.88%RedLineStealer
2021-07-24n/aexe 0fbccc26213ec041b38565416c423bbf000c8ff5fef6f2dd4ca1bcb112bc4794Virustotal results 71.43%RedLineStealer