URLhaus Database

You are currently viewing the URLhaus database entry for http://193.142.59.119/forum/images/file1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1538190
URL: http://193.142.59.119/forum/images/file1.exe
URL Status:Offline
Host: 193.142.59.119
Date added:2021-08-16 05:38:07 UTC
Last online:2021-08-19 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-16 05:39:04 UTC to abuse{at}hostshield[dot]net)
Takedown time:3 days, 2 hours, 4 minutes Bad (down since 2021-08-19 07:43:41 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-18n/aexe 557e756dfca6b7c77f7027c7d951849cbbdfee84100a478b7d7ff6ef3bdbdf7bn/a RedLineStealer
2021-08-18n/aexe 7085fd0fa11f6237230e71b7903262d1a6e9420c355673055f71e55ebaba6744n/a RedLineStealer
2021-08-17n/aexe 6fbaa6d2625f015db74867e78122bead2905e5e1193697d1d361f97931142e6an/a RedLineStealer
2021-08-16n/aexe 9fe6d5f26dd379278e64d52d402e4e818384998d224fe8ff6c1c25a9474321e1Virustotal results 21.43%RedLineStealer