URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.10.214/US/PB12.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1548971
URL: http://37.0.10.214/US/PB12.exe
URL Status:Offline
Host: 37.0.10.214
Date added:2021-08-20 11:28:04 UTC
Last online:2021-09-07 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-20 11:29:04 UTC to abuse{at}serverion[dot]com)
Takedown time:18 days, 5 hours, 15 minutes Bad (down since 2021-09-07 16:44:26 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-06n/aexe 8aa0059a4ae43e6dde91f3ffc8f0d14792a2c98bbee36ce77b0bb4befd8a48ddn/aRedLineStealer
2021-09-01n/aexe b3f56155505f07b8cf4a381d245d689f5609f10e29f5bc6e9d3046223ad4569en/aRedLineStealer
2021-08-27n/aexe 9839e455ba50a03657cd2cdd70ff5946652031aa69eb6e665ec5e01fe5441accn/aRedLineStealer
2021-08-24n/aexe e031bb84afc57bbdff6ab04d1bf56b714c8744462afcb60b6d02928e49872aa9n/aRedLineStealer
2021-08-20n/aexe 65b93f1505201eab6ac6e7d516db7afca0efcad6157dc666684dfc6c7caf5458Virustotal results 40.30%RedLineStealer