URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file6.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1642901
URL: http://2.56.59.42/WW/file6.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-24 21:43:04 UTC
Last online:2021-10-05 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-24 21:43:04 UTC to abuse{at}serverion[dot]com)
Takedown time:10 days, 23 hours, 48 minutes Bad (down since 2021-10-05 21:31:26 UTC)
Tags:32 exe RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-05n/aexe f1f165d41b6bc5b677842d07f1a7481450aaed1ef45996e10777c2c7a3868737Virustotal results 37.68% 
2021-10-04n/aexe 2df2718b04f95688fbef6c3d1e3a284f8a02d3d3389a9b0261aa9a4a6f26d2f2n/a RedLineStealer
2021-10-03n/aexe dd75325c7035eee20647ca9d5a101167165d2dba88f6bf54a7afc50c276aba90n/aRaccoonStealer
2021-10-03n/aexe 542d3afd8e53c760dc33fe8e0ca225c3387b56a9b951414796353b8e927e05a6Virustotal results 29.85% RedLineStealer
2021-10-01n/aexe e62e88acbf8d8ab50b1247aed0eae664c92b1cdcb11220c367749a7be04596aan/a 
2021-09-30n/aexe 76429272073848a3e62ad51d536c114ed5924ae283f24e7bbc1d67732d226eben/a RedLineStealer
2021-09-30n/aexe 21d0bd54f31a7b35e073f461a6cf22015ffb76314f36d152e03d3210684bf200n/a RedLineStealer
2021-09-30n/aexe 9343cdf6d2394e96a588e4be22c194ed5b7d8a22ea59b9c08797a807c18db78an/aRedLineStealer
2021-09-29n/aexe 9a75a39de0d9bdf4a62a78d1050a259c6cf0db4f75f2695cec176fb1278df7d9n/a RaccoonStealer
2021-09-28n/aexe ac098ff6d0aab414dad2bce4a4a21ade100a6d4921bf90c7890409b8d37dea05n/aRedLineStealer
2021-09-28n/aexe f4268cb916f236bd1a7c79e4da42cdf09806b6a7e09038db725518f1c7e0cc60Virustotal results 36.76% RedLineStealer
2021-09-24n/aexe 14f35f0cd672f0dbb8eb4c3888fd6407897c3f7307ad7ad57b949a0c7c11ab81Virustotal results 44.93%RedLineStealer