URLhaus Database

You are currently viewing the URLhaus database entry for https://iridium.services/download/SteamUpdates.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1528971
URL: https://iridium.services/download/SteamUpdates.exe
URL Status:Offline
Host: iridium.services
Date added:2021-08-12 23:12:03 UTC
Last online:2021-08-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-12 23:13:02 UTC to abuse{at}serverion[dot]com)
Takedown time:15 days, 14 hours, 25 minutes Bad (down since 2021-08-28 13:38:56 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-21n/aexe 749d16132ff94c8da68f477d2f506ec2e5ab5bcd481c9f2d57ecafdd3b5ffa45n/a RedLineStealer
2021-08-18n/aexe f63134b547063819145178f8799cd78acc9c8d59eca4fa4b67d9f31810f51b23n/a RedLineStealer
2021-08-16n/aexe eb59b0429c4868af203cfe4029a4327b8fd81233d78f104123d1501f2d273b32n/a RedLineStealer
2021-08-15n/aexe 40b77ae59274ca3ed3fb9ff6604b0dab27e216ae73e35c15496f7f0d028634bfn/a RedLineStealer
2021-08-13n/aexe bbe0f74fca386e4bd78dd21c03f4b9f6086691318d684caca0fecb2122d28961n/aRedLineStealer
2021-08-12n/aexe 9519d8fd2da2a5e3c3ffa2a490c851946da030910c91ce2db392c9aa464bdd5fVirustotal results 26.09%RedLineStealer