URLhaus Database

You are currently viewing the URLhaus database entry for http://193.142.59.221/blog/images/sw.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1528443
URL: http://193.142.59.221/blog/images/sw.exe
URL Status:Offline
Host: 193.142.59.221
Date added:2021-08-12 18:15:05 UTC
Last online:2021-08-14 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-12 18:16:02 UTC to abuse{at}hostshield[dot]net)
Takedown time:1 day, 12 hours, 25 minutes Poor (down since 2021-08-14 06:41:45 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-14n/aexe b9633b58b49a6a78d540d8d96397f22dace1bc1ff523edde253d190a9080e938n/a RedLineStealer
2021-08-13n/aexe 4f7dc521eb2533dc5441b10fa3011e57dbb301c4f67e72adfd83130a967e74ffn/a
2021-08-12n/aexe 5d682001504dc58701765ca9721e4b4b9eb5b5e73469731fe787d15217cd7435Virustotal results 22.06%RedLineStealer