URLhaus Database

You are currently viewing the URLhaus database entry for http://host-coin-data-1.com/files/794_1637838750_2902.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1817979
URL: http://host-coin-data-1.com/files/794_1637838750_2902.exe
URL Status:Offline
Host: host-coin-data-1.com
Date added:2021-11-25 23:14:09 UTC
Last online:2021-11-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:4 days, 16 hours, 20 minutes Bad (down since 2021-11-30 15:35:45 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe aa05981c131fe7500f5ddee9b5856060ecafab0823d8668485f4a6fde88a03fbn/a 
2021-11-28n/aexe 5926d0c6d11f86a7c41f4d379201430fae8baeacb56a46f4cefb97371e6d35fen/a 
2021-11-28n/aexe 6d1c0e6b3b659d518c75addbc8c24c00784c58b06f326f2a7e9e0ded97ecff01n/a 
2021-11-27n/aexe 161e1da74105b5194f3f2e73ad14af51a69f51ac6e8799b1044609724b24a41bn/a 
2021-11-27n/aexe 4dd701763655288f33c05756d3b9513f01de85d191fcd6b754375b4550750af1n/a 
2021-11-27n/aexe f270c4f88a4c3495476aab9aa16c81aae15078fab384dbc14253a9fd3aec4431n/a 
2021-11-25n/aexe 69b94cf02460d47d69d44a5ed4b07fab06737c0eaadbda9bce6ba87224622aadVirustotal results 35.29%RedLineStealer