URLhaus Database

You are currently viewing the URLhaus database entry for http://45.147.228.157/wp-blog/pics/sefile2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1573116
URL: http://45.147.228.157/wp-blog/pics/sefile2.exe
URL Status:Offline
Host: 45.147.228.157
Date added:2021-08-28 20:05:04 UTC
Last online:2021-08-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-28 20:06:03 UTC to abuse{at}combahton[dot]net)
Takedown time:2 hours, 47 minutes Good (down since 2021-08-28 22:53:16 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-28n/aexe 139f9630abb39fd774ae971e867ae2147ea50070b2e8af8ba4248969ba40504en/a RedLineStealer
2021-08-28n/aexe f3063e281ba79321dfb154de1437496598691b2369ea9ca6974904b63de7603dn/a RedLineStealer
2021-08-28n/aexe 75b153ab956df323cae26dd5b14b64fa8a39828e86c0acd3204ab0a63ae42ec5n/a RedLineStealer
2021-08-28n/aexe d319ddd3d52abce88199f3b7d1385bb3258290139b8b05a1ef2b672af8da2fbaVirustotal results 39.71%RedLineStealer