URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1642880
URL: http://2.56.59.42/WW/file5.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-24 21:37:04 UTC
Last online:2021-11-25 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-24 21:38:01 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 1 days, 22 hours, 24 minutes Bad (down since 2021-11-25 20:02:53 UTC)
Tags:32 Amadey ArkeiStealer link dcrat exe RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-25n/aexe d8679264a11afc0b391e03d50b726be456e8d24659fe907745bae7e58abb66ddn/a RedLineStealer
2021-11-25n/aexe 9564a0a46db48c66eeb013cf91be5ba75acf48a7a59a5e237969ff4313950b8fVirustotal results 33.82% RedLineStealer
2021-11-22n/aexe fadb8eb7a7e20388dd3f9cf66171ae8d1c1e0845aed740ea58fa432c69bbaa7en/aDCRat
2021-11-19n/aexe 65eebaf9df948bf4eb793e880ae425729b9f51b14fc9a4f64530819aba8c3097n/a RedLineStealer
2021-10-14n/aexe 020110f827d739393492ebad4dfea2e61792998044bc184843375c5e2cf1c572n/aRedLineStealer
2021-10-14n/aexe 9bc3643977e00cfceffd956c7bffc7cd768d939deb3765da0c865e7c1d1c1c30n/a RedLineStealer
2021-10-14n/aexe 9837c7031b7f69b212d74ca697ae7edd53f1185eedb80e00b6e2777e41f06bccn/a RedLineStealer
2021-10-05n/aexe 13f9f1b052c5d540b5dfa64f9eafcb962163d3649d222bbb8690182741622420Virustotal results 50.72%RedLineStealer
2021-10-02n/aexe ff96c05cc539eae59ea43c37f1996372589b33aa2ba3a9bdc5a1e7b20b1f75b2Virustotal results 55.22%Amadey
2021-09-30n/aexe ec9982a34d254f2d78122c3409e2bed7295abbe83c736e746f5037f1bbdf9c6cn/a RedLineStealer
2021-09-30n/aexe 93213a44c861db58c20e17afe5c5d0bfe63f9faf7aa7926bf6df3522dc73e35en/aRedLineStealer
2021-09-30n/aexe 797a69e3e8bdc39f1e0dcb6fafce13a661f8fda89cf89c7a9453cf4f6430f6fen/a RaccoonStealer
2021-09-29n/aexe e5e0601b8269cf5ffd12af1b005d913fd5d70235841daf3017a9cbb5da483dcen/aRedLineStealer
2021-09-29n/aexe 950bfa5ec6f7e8987aeb2bc6584d18bd3ef83942aa73c3c42faa9389030f0691n/aRedLineStealer
2021-09-29n/aexe b78c36dc5a9215fdc28d52f0f50dc68a82e8ce7061ce9f033ed2631a9b06fda7n/a RedLineStealer
2021-09-28n/aexe 6f249140cd20e91a196d7e5ca978e74a18c4d30a7f2f220627f6ef044e5a3056n/aRedLineStealer
2021-09-28n/aexe 181f85bb6d83fc1f8a88a320a4ac8052ce5e5952a76147ca321eb7967a142fc5n/aRedLineStealer
2021-09-27n/aexe 1f4ccad233d733ecf2c0374593f95ea0bd521a17e82206b17fd74948faca974cn/aRedLineStealer
2021-09-27n/aexe 5e88cd141556c3b8305bb6f6e68154b27765ea3b512d9843463d6fd99616ad02n/a RedLineStealer
2021-09-26n/aexe a335a14188c608ba63b172cb891cd710c2bae0d56816c264f65037600d78e4e8n/a ArkeiStealer
2021-09-26n/aexe a5228f1d1c83f629bcbe9dd896ea0146536c3062d784b4f423b8067637bb89c4n/a RedLineStealer
2021-09-26n/aexe 2f802aab0b83ba927a253910e4fb2a071f39c5515d08e29be2c2a687771be0d5n/aRedLineStealer
2021-09-24n/aexe 1df60e1cc475438904d4748169d9c0d33535b6dea492607d664fac917c518e01Virustotal results 42.65%RedLineStealer