URLhaus Database

You are currently viewing the URLhaus database entry for http://host-file-host9.com/files/8962_1637425998_2979.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1802474
URL: http://host-file-host9.com/files/8962_1637425998_2979.exe
URL Status:Offline
Host: host-file-host9.com
Date added:2021-11-20 20:38:08 UTC
Last online:2021-11-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:9 days, 18 hours, 45 minutes Bad (down since 2021-11-30 15:24:22 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe 99154a47f7ff4c2328b8ad983baf1dea2789dc6f2a1b768a2ae1ad8c9ab51d35n/a 
2021-11-27n/aexe 8262eec7b9ecaa4b8a183d91147d93d7b9ed2f25362d7f5aed00176fb34b4932n/a 
2021-11-27n/aexe c6d0508fd1831d4aa7ee76d1b22c9ebc37cea26377c30351665b4feed5bd3d2cn/a 
2021-11-27n/aexe b64a7dec041ea1e714adcc6893ac02d9534ddf89765db8ed643b4e1033646172n/a 
2021-11-25n/aexe eb54d274bd0e534225fe5cb1809d97ae91a9cd40bd755d73e19c619a16f50f0fn/a 
2021-11-25n/aexe 9ffa0227bfcaf5f243d964c5411417fca6ea6bd58118dcc85b25b3582ac41c26n/a 
2021-11-25n/aexe da7d4109ee3d0ae0309cbf119c5cbaccb277676e439187307057114a813faa40n/a 
2021-11-25n/aexe 28a6b6ce1c92de9224dfab9a9f853113c5914fa16658d9a452a79913b3c9f6fdn/a 
2021-11-25n/aexe ccf3d537a02bbca791461fb02b9b6ebfb1e1395a21cdb85e8a979974c6c3881en/a 
2021-11-20n/aexe 8df75aad857d0f7b14d033e17b101104d6ea4baad173cd1f5b43105d630dde0an/aRedLineStealer