URLhaus Database

You are currently viewing the URLhaus database entry for http://host-file-host9.com/files/7416_1637431621_5237.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1813946
URL: http://host-file-host9.com/files/7416_1637431621_5237.exe
URL Status:Offline
Host: host-file-host9.com
Date added:2021-11-24 20:07:09 UTC
Last online:2021-11-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:5 days, 19 hours, 26 minutes Bad (down since 2021-11-30 15:34:28 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe a835c6c1950d810cc313f4bca794767bc2e62a41f4fc9062ca245374c13a76b7n/a 
2021-11-28n/aexe b31f13417a75667808b78b6da9bfd8e18fa1e1cbde7550521b3b2f0f3f93798an/a 
2021-11-27n/aexe 3f6c9dfc95aa7252f1aab8ada601b882aec440bfabc090ce46db68a87c184f6an/a 
2021-11-26n/aexe c4ac71c963eb8fbe8c46995092aad48ac17052a28dee69f6b10ee455f551c965n/a 
2021-11-25n/aexe 48d1e3d4d41a99282fb6fe50bcde6b9bc842908d88c907b40c3ababcae95ee32n/a 
2021-11-25n/aexe fff7184d7eadcfc6037c65e1c9bb8a72adfedb9afd193b587b4a25df19048ec3n/a 
2021-11-25n/aexe 1fc7922939866e65d7ecb06ea7b7866e879f10693252583b11338c717764bfb8n/a 
2021-11-25n/aexe f52e242620adf6c90369c086f3f4696961af9b2d0dc38587bab7aefa2b8b41a4n/a 
2021-11-25n/aexe 4cb88e0aa6495bb23098fb179f64f905e9b6f288ccae26986be4cc1d0a4ebb2dn/a 
2021-11-24n/aexe 53be781d925c90c28f700293c4713000ab42cc43412b9532f69b4d0ec3b5a0f6Virustotal results 54.41%RedLineStealer