URLhaus Database

You are currently viewing the URLhaus database entry for http://45.137.190.166/clip.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1493959
URL: http://45.137.190.166/clip.exe
URL Status:Offline
Host: 45.137.190.166
Date added:2021-07-30 23:36:04 UTC
Last online:2021-08-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-30 23:37:04 UTC to bitweb{at}abuse[dot]network)
Takedown time:23 days, 9 hours, 27 minutes Bad (down since 2021-08-23 09:04:50 UTC)
Tags:dcrat exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-08n/aexe 58149a24884e425f40c7f2dfd541e5380573e4dccf270564b4ae71df235bbc87n/a RedLineStealer
2021-08-06n/aexe e7a12f2910eaa2aabc347d0ce882f83662a02c0369fc0e59df98bd6833a712c2n/a RedLineStealer
2021-08-05n/aexe e12e033163205721012606e52c60f7c23730ffe57c0adcae7f4193ef9e47e9adn/a 
2021-08-04n/aexe 69051caca63e511a3921df1bef3a5f87155b6b56a5d57293c172929f5f170cd6n/a
2021-08-03n/aexe 924e18d95c8ab8d55d962b7c66539a8dc94fb3109e755f127793116038d470aen/a 
2021-08-02n/aexe ecd7a281c1f3a500a0ed2e6c745c965ae725bcea75e9d7b6a5520eb41dc79cd5n/a DCRat
2021-08-01n/aexe 30320c23745d14085669f891d3805c6fb3823496cbea8fcae4384cfecd505f49n/aDCRat
2021-07-31n/aexe 88c642b1fa43b77487f3916dd95ac236189971475c3289c745dc45a739e6453fn/aDCRat
2021-07-30n/aexe 0389ffef740d3bd365f2b699ac006b478a5346a1dc2383e10fd5152771641c0bVirustotal results 42.86%DCRat