URLhaus Database

You are currently viewing the URLhaus database entry for http://installcb.ru/CurrenyCalculatorInst.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1627245
URL: http://installcb.ru/CurrenyCalculatorInst.exe
URL Status:Offline
Host: installcb.ru
Date added:2021-09-17 09:12:18 UTC
Last online:2021-09-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-17 09:13:03 UTC to abuse{at}reg[dot]ru)
Takedown time:4 days, 0 hours, 38 minutes Bad (down since 2021-09-21 09:51:15 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-20n/aexe 986ec8c30ab4281161bc7861e47f6bc2cde8960db915da07bc1eade6865018e9n/a 
2021-09-20n/aexe 670906ad0855a2402291c290dc16f18343be80a00cb7f164463475b2fbf132b5Virustotal results 34.78%RedLineStealer
2021-09-20n/aexe 39f5b13c60418f4bcefdd1df075a6fe9e8bd879340c42d12c8a5e636aa035e6dVirustotal results 65.22%RedLineStealer
2021-09-18n/aexe 6a498d84dd0cba5d8e272cbc5cb10382e7fd0da648a345e92c26414ceb5d3dc8Virustotal results 59.42%RedLineStealer
2021-09-17n/aexe 13d8d9a03df3f510c71149a3c9ccaa4570172e45b34463d16e85a008a57469bfn/aRedLineStealer
2021-09-17n/aexe e313b4fd124a57681c954a72c3a09aa4fd96245df42130fc6ddeaa10d6a4451cVirustotal results 35.29%RedLineStealer