URLhaus Database

You are currently viewing the URLhaus database entry for http://blairwitch.top/work/mix.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1817128
URL: http://blairwitch.top/work/mix.exe
URL Status:Offline
Host: blairwitch.top
Date added:2021-11-25 17:20:12 UTC
Last online:2021-11-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-11-25 17:21:09 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:3 days, 23 hours, 30 minutes Bad (down since 2021-11-29 16:51:29 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe 48add86964981ab1438afe14132049fb2366e2f42d53e244be3518e277c3b0b4n/a RedLineStealer
2021-11-28n/aexe a67a1f57340a32eaa9e77984ba814ba4e0264af488dea075b500bcceec999c0eVirustotal results 41.54%RedLineStealer
2021-11-26n/aexe 711fb0f713f733d48f5f010d42d1bf8dbf222f53ecc7184585c6bfcc4b2566e1n/a RedLineStealer
2021-11-25n/aexe fe04cc4e48dde55f68dd1c53847aecc7bc6a25304aaca3b37e3d1b2f8e63be0en/a RedLineStealer
2021-11-25n/aexe 2934bd9eae57bdf2b28f963a32b4e916d739427e8de096df007fc0eed5a1f910Virustotal results 52.24%RedLineStealer