URLhaus Database

You are currently viewing the URLhaus database entry for http://147.124.222.75/Reds.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1488364
URL: http://147.124.222.75/Reds.exe
URL Status:Offline
Host: 147.124.222.75
Date added:2021-07-28 21:00:04 UTC
Last online:2021-07-31 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-28 21:01:03 UTC to abuse{at}spinservers[dot]com)
Takedown time:2 days, 17 hours, 43 minutes Poor (down since 2021-07-31 14:44:33 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-30n/aexe b5b2b8256bc3ee6e110d768d7937c3d5f8f573b7aa7cb4af83fc250eaef1d089n/a RedLineStealer
2021-07-29n/aexe a57d43d2884bab0ab08a34eaa49c96047e6253aa6b3f1e6b3b02ce9325652617n/a RedLineStealer
2021-07-29n/aexe 94a1e49bc60423c53851e106d851164e1163b5abb60c53276e3fb9f4f912ef63n/aRedLineStealer
2021-07-29n/aexe f86b4814a1e6f31eb35812e649f44fae6bd0cd9b94a59cca3d83c0d6fef5a1a0n/a RedLineStealer
2021-07-29n/aexe 971d4e570da6e6dc760a1d574710ee3cd23167af82559a836180cd5e028333b5n/a RedLineStealer
2021-07-29n/aexe 68c2185d91ebdcdc8d177bc85e0565caa9ef6e833d0207740f1caabbe4e8aba5n/a RedLineStealer
2021-07-29n/aexe 5c0a1467d4d8cf4a87d15dc25d06706a4100bffc4969dac8e216551802e63c2fn/a RedLineStealer
2021-07-28n/aexe fca68250f0af2ea4d2ae1747c92b89e67799cd41db4b6dfe8eed57cdcf1cb07bVirustotal results 33.33%RedLineStealer
2021-07-28n/aexe eeb882e1d0487c43be9d91050b9ec7eeee5e2e1d315cbbb715e983a7a9ba99e5Virustotal results 40.00%RedLineStealer