URLhaus Database

You are currently viewing the URLhaus database entry for http://host-file-host9.com/files/9997_1637333287_4814.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1802662
URL: http://host-file-host9.com/files/9997_1637333287_4814.exe
URL Status:Offline
Host: host-file-host9.com
Date added:2021-11-21 00:27:04 UTC
Last online:2021-11-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:9 days, 14 hours, 53 minutes Bad (down since 2021-11-30 15:21:35 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe 794578da3fa2815e44031f81d78bc0b044dc715c4b6841ed396abf85bef55d1an/a 
2021-11-28n/aexe 183a9dadf51be06fee56262b49e5f721386fe266e037c3ac69b4520662aad89an/a 
2021-11-27n/aexe 18303aeb45d9a4813b8ae5ed1753fc61c16bc2a7a8c7eb1a7d55f12273cf5071n/a 
2021-11-25n/aexe 3bbd0097d54859bbf2d6f7767b56d2bdce11778b596b13c4066c4b2650db334en/a 
2021-11-25n/aexe 4cbbe55983e9e4c611d49dc4573da081b9820c34e2e81bf3f6889ef13e7b8f41n/a 
2021-11-21n/aexe 103c2aee0f0701bb47ea101d3fda6d995385a1113552734ac93136fd2806b917n/a
2021-11-21n/aexe fa7c9ceef8e12f93b19281b92959d1dc58b673d3a0486f7bb87e0198a7b78ee2Virustotal results 25.37%RedLineStealer