URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1642879
URL: http://2.56.59.42/WW/file2.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-24 21:37:03 UTC
Last online:2021-11-27 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-24 21:38:01 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 3 days, 7 hours, 6 minutes Bad (down since 2021-11-27 04:44:10 UTC)
Tags:32 ArkeiStealer link CoinMiner.XMRig exe RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-27n/aexe f15e77a9002b5ff912240ed81aeb0ab548871d5efdd09972bcdadb153198bc68Virustotal results 44.12%CoinMiner.XMRig
2021-11-24n/aexe be49298a70c5aaddc5abe883d615f25b62909f9b3533485af9752216a03ada00n/a RedLineStealer
2021-11-24n/aexe d9a49f7ccbb17c3552c3a2ba2a60cc0fc2a96268671cdbc5d864bb643bde453fVirustotal results 30.88% RaccoonStealer
2021-11-18n/aexe 1f32c94f55bcefb65e8f03108025a8439afa500ae6a5bcba56e762c168e96e67n/aRedLineStealer
2021-11-18n/aexe a127a597c69f6084d2076b1f4853404dff77dfb5a1e4f1e8d57516ab035ab0f7n/a
2021-11-18n/aexe 36bd5c9ee48bc187184cf4cc9958a54ed65d04bc4a3cab022de3ede4277c97afn/aRedLineStealer
2021-11-05n/aexe 6a020c5b103af93257680f7ca1d11c08a5b433958e1ecfd81bd4b67a61774364Virustotal results 29.85%RedLineStealer
2021-11-03n/aexe 06a9759ea9b28bc0247d79aa3d5d0987f98b14f1caf8f25748a95617593b88adVirustotal results 25.37% RedLineStealer
2021-11-02n/aexe 4c8c47cca539b9d2b0cf3202ff102fa23140271cba9ddebdab27d8b4fc9ab796Virustotal results 16.39% RedLineStealer
2021-10-29n/aexe d6970d01f1f0eb110e3be4837f67062b27bcf9960fb4deca4487862018c63bd6n/aRedLineStealer
2021-10-29n/aexe f5c9906c890964cdb35784f14e6a26f09d9ebd357df901616330b02c35c4e286n/a RedLineStealer
2021-10-19n/aexe b7fe47f9edb0d092410ebcde250bf62190bbbefae8b93b671f4f8eaa70ed30afVirustotal results 62.32% RedLineStealer
2021-10-16n/aexe 7824fed890e9a0707d2e3e4cc06f76928a501252ff5c01ce5d17d861f8f7f4a1Virustotal results 23.08% 
2021-10-09n/aexe 9dc10b45a72d48a04e7246a4223690d82ea0b206edee5d7e6b19bb5b3935d122n/a RedLineStealer
2021-10-09n/aexe 02699d82bbb4b85d9785a6cd83fd639382ffb848d2a4abcadf503a5b766c5af6Virustotal results 26.09% RedLineStealer
2021-10-08n/aexe 4892eccf81c41da00c2fe4dcd535f2691db8e9d39cf386d734f0d774f40898eeVirustotal results 33.33% RedLineStealer
2021-10-06n/aexe 8d9ed28e4ff869fb32f2f4a97c12d40c43942e72a31e9c14c3ce6ddfa0eb63ben/a
2021-10-06n/aexe 1abadd3fb21dbf1da2254539c73517d2af43ef9bdc3c67de66466fb961cb3fe6n/aRedLineStealer
2021-10-05n/aexe 155ba4e7e296e9c66eba8f7a75e7f05f51751c97dd710ec6d2c064e7fb882734Virustotal results 43.28% 
2021-10-03n/aexe ff144f47f95b7b8f24573fc07b29562fdff19ea4a0d784e5c122995ab42095adVirustotal results 37.31%RedLineStealer
2021-10-02n/aexe baabe1f7bf9f0034037f5ed924b0b3e5637fea32e63c83c2321e088259384650n/aRedLineStealer
2021-10-01n/aexe 455f27d80de4e45fd405ae467ed2a7b9f8a1e050a27833d79b9ce05a6d72cef4n/aRedLineStealer
2021-09-30n/aexe 34f7e6d67241516c988b59200389016b5a1a15846104d10d0a7a790e60732ee3n/aRedLineStealer
2021-09-30n/aexe 06aee363e50d05049ccaf2f00bcfc05cc35fb1f96359ed08141d3188ba9df5c4n/aRedLineStealer
2021-09-30n/aexe 446736e381fa8942f8d32cb4f2ae8fb6a9245fa0e70b7f7298ee7a5cb6fe9f32n/aArkeiStealer
2021-09-29n/aexe 167e4b919946be4b03591e3eceb19b37e9882200af7450dca4ba4891af36bea7n/a RedLineStealer
2021-09-29n/aexe d61d33074ee4ad694efb6573a5f40923cd31c96d78a9a54934c11e0671766b8cn/aRedLineStealer
2021-09-29n/aexe 5e4d5246c1a9a051321fefef3bc3b37e4388712a6b090acf0bd61aacd23a1f59n/aRedLineStealer
2021-09-28n/aexe 4c889775a4fa2bad1bc56a20169cd221eea94eab6d236da1928af5535071ecaen/aRedLineStealer
2021-09-28n/aexe 035ffcab1903dbf2f58155dfb50c14f2463e01fe9cf46baa4cf678f7e6b255ffn/aRedLineStealer
2021-09-28n/aexe 92cfe38fa5ebff038c426486d0ef7d85e7cf8bde070d94350dc1d1b376a528c6Virustotal results 55.74%RedLineStealer
2021-09-27n/aexe b3c5e8250ec320fd546df876a5be7ca4e9a70696dc2373ce5ff670def95d5238Virustotal results 39.13%ArkeiStealer
2021-09-26n/aexe 9ee3f359c016cb3cf41ad7558cb18e92e224658b75e6b082b103ba293298a79fn/aRedLineStealer
2021-09-26n/aexe 92d143b6d646385bfd05527662ea674b51e01988dcf44018250e0e89ecc3d5cfn/aRedLineStealer
2021-09-24n/aexe b895219019dbaa9afade06641510e9263ac2f6258dd79d0a0ad44406abeaf96aVirustotal results 57.58%RedLineStealer