URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file10.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1644583
URL: http://2.56.59.42/WW/file10.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-26 15:29:05 UTC
Last online:2021-10-01 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-26 15:30:03 UTC to abuse{at}serverion[dot]com)
Takedown time:4 days, 10 hours, 46 minutes Bad (down since 2021-10-01 02:16:43 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-30n/aexe 4adb694efcbcee94dd7aba7cd8d717eeccd06239bfb89555440f2d5506af8b90Virustotal results 32.84%RedLineStealer
2021-09-28n/aexe 8c31c918be36cca7c909cc2b96c0d98b6594511220d11e355d72ee6ab3aa29f6Virustotal results 49.25% RedLineStealer
2021-09-26n/aexe c8d4d7e0437c1860e11090a0ae3ae3bd38272052fbd1ab78eb5f017d13cecc1fn/aRedLineStealer
2021-09-26n/aexe 1e31f411b06517388b7adbcc5bc918f3985d447f710aa9711926faf68d044f9an/aRedLineStealer
2021-09-26n/aexe 31ef0139218354a140f9feba6fc3ef036ce910a84babf8f27cccfa944dee1ccbn/aRedLineStealer