URLhaus Database

You are currently viewing the URLhaus database entry for http://host-coin-data-1.com/files/5678_1637930808_5847.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1821295
URL: http://host-coin-data-1.com/files/5678_1637930808_5847.exe
URL Status:Offline
Host: host-coin-data-1.com
Date added:2021-11-26 21:08:06 UTC
Last online:2021-11-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-30 14:19:03 UTC to noc{at}baxet[dot]ru)
Takedown time:3 days, 18 hours, 11 minutes Bad (down since 2021-11-30 15:20:17 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-28n/aexe 33e998b8ab10d5dfcd8def6e1ea3ba802b68e70b21cb23083fbf99a603bd945fn/a 
2021-11-28n/aexe dee1f1e6effd8bbe057bd9a66d26cb46087b6b01c180aeb4ddb593db7c11d117n/a 
2021-11-28n/aexe e09e47f2c23c4617769d903d3d4d2cc75b55bd371acfc67eabb334d8d3ec9611n/a 
2021-11-27n/aexe 5ab61d6b47f24652fc0bbd303bf2c0e19c4584d2542bee41fb1d2ac5595a22f3n/a 
2021-11-27n/aexe 0be7584fe128ca2c0d22307c35d37e48e4c4f9cdc83c2132fb6ea0956c50ab2bn/a 
2021-11-27n/aexe 8fba7509f85265eaf64b3153354f56c36cd77fb295a2d9830eb43da4422cfb76n/a 
2021-11-27n/aexe c5a2fe0b59e41ee8087034103ee5c896aaf4d8510ad56929cbeb270df5029f53n/a 
2021-11-27n/aexe f86e4eac43a1ab814b30c8654321c7cd01579eb0f95eaa01aafccb3372520a04n/a 
2021-11-26n/aexe 3ccb921993ccaf52af063cfaae2e31df9101befd6553a5a4631367416116c412Virustotal results 18.33%RedLineStealer