URLhaus Database

You are currently viewing the URLhaus database entry for http://host-file-host9.com/files/4273_1637345922_8676.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1801391
URL: http://host-file-host9.com/files/4273_1637345922_8676.exe
URL Status:Offline
Host: host-file-host9.com
Date added:2021-11-19 19:30:10 UTC
Last online:2021-11-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:10 days, 20 hours, 3 minutes Bad (down since 2021-11-30 15:34:22 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe ff526c878900869cf1ec0510a4c0ac0d42f42264774125ed71495c79ac13754en/a 
2021-11-28n/aexe b26a623b3e13f3c60c79697fcd1f4b7a24527307f32618ff2d703531223a3d2fn/a 
2021-11-25n/aexe 23c3fc77c61198fbb335da81766724aad6c22f35e0263930b7893afa2cc21357n/a 
2021-11-25n/aexe ee2f34fad0e9c456112c97652d96c82b9ce880b495614eb9f8a11a107cc90a37n/a 
2021-11-21n/aexe 4c4cf8d668c66931d65d127a4a630888a13a51f612fcfccb554a16696ddf4546n/a
2021-11-19n/aexe ec75d2e78898eef0f85ec90d16989cf9c1fb5f1e0f7b45cddad67192846aa8dan/aRedLineStealer