URLhaus Database

You are currently viewing the URLhaus database entry for http://138.124.183.115/file/goodjob.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1576837
URL: http://138.124.183.115/file/goodjob.exe
URL Status:Offline
Host: 138.124.183.115
Date added:2021-08-30 06:07:04 UTC
Last online:2021-08-30 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-30 06:08:03 UTC to abuse{at}pq[dot]hosting)
Takedown time:8 hours, 49 minutes Good (down since 2021-08-30 14:57:55 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-30n/aexe 154a204db187ba267e196eb9a262ac9b7915ca1488966a2e897564cbe7d42ccan/a RedLineStealer
2021-08-30n/aexe fafcea6d703c4484e8ab2e3a3e154ab860ca0f83657567b1f9df504362ad94afn/a RedLineStealer
2021-08-30n/aexe af5d675cf052c82adbe3a3fa8f49d69f7832dac4287990975796600f96ac8036n/a RedLineStealer
2021-08-30n/aexe 0c4f49f470680e6181c19777ebabc6a780cc0c30b2d9dbc2b4f65f9c635ccdd2n/a RedLineStealer
2021-08-30n/aexe cc1b3e18520c1f5ae7040cbfd2d74c9d3e5c3c47aa01d44d1037fffcbff96564n/aRedLineStealer
2021-08-30n/aexe de86bccb5f3ceaa1046331b7edca54e263455a993ef526d8b203470b1cb2a9ean/a RedLineStealer
2021-08-30n/aexe a2485dde0d77f29ddfbaa4c2e8df06924fb2a02a1288242063a4b4a1e754e75cVirustotal results 40.91%RedLineStealer