URLhaus Database

You are currently viewing the URLhaus database entry for https://futurepreneurs.eu/wp-content/plugins/dn-events/DownFlSetup166.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1684798
URL: https://futurepreneurs.eu/wp-content/plugins/dn-events/DownFlSetup166.exe
URL Status:Offline
Host: futurepreneurs.eu
Date added:2021-10-16 10:54:04 UTC
Last online:2021-10-16 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-16 11:00:06 UTC to abuse{at}telia[dot]lt)
Takedown time:6 days, 0 hours, 22 minutes Bad (down since 2021-10-22 11:17:26 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-21n/aexe 0171e9e9eeeb770d96f761afc719ec455f1798fa81f7a0bf99854ea08a11b5b9n/a 
2021-10-20n/aexe ab759d4dd1159da2f15203da815fb8568137811a4481354951827e6dc7263b33n/a 
2021-10-19n/aexe b6cad5d4a2feb77c496cf7d7438de7a977127302dc699de1f92d5812cee009d2n/a 
2021-10-19n/aexe 3e66be1ab42337c8396e71b2068484c3cf786bfefccc3c50114330ff5c080f23n/aRedLineStealer
2021-10-18n/aexe 8b5159129cf91470eab5590ee6ef5b2db0acabe7cfcd8f99b17a0c9aa88ff8f5n/a RedLineStealer
2021-10-17n/aexe 114d1bd84bdb0254fc4dbd097ff4967ade6c0468d77ca25b9e10c4b5beb99160n/a RedLineStealer
2021-10-16n/aexe e5c7a8e3c41afa656fe8a0db72a99f86f93aa4085dd1860aa1dd67099ac228aaVirustotal results 28.57%RedLineStealer