URLhaus Database

You are currently viewing the URLhaus database entry for http://212.193.30.29/WW/file4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1862409
URL: http://212.193.30.29/WW/file4.exe
URL Status:Offline
Host: 212.193.30.29
Date added:2021-12-07 10:53:03 UTC
Last online:2022-05-24 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-12-07 16:33:20 UTC to abuse{at}des[dot]capital)
Takedown time:5 months, 17 days, 14 hours, 15 minutes Bad (down since 2022-05-24 06:48:26 UTC)
Tags:CoinMiner exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-23n/aexe 395ff77cd5c64b67d071553403735b6e507ce2903d862d3263e5357f20408e17n/a RedLineStealer
2022-04-11n/aexe d87d068e5cb1719d523dbeeff0306d360ab4d4f4efa1ba6accf61b2c3a5516e1n/aRedLineStealer
2022-04-08n/aexe 0fb2ff7374e2ce9e837fc8d3077d89f1f7443d0088d3260b3c0b7a17eae3e849n/a CoinMiner
2022-03-29n/aexe 60fe37cf569a1dbb5b31fc694c6323e4e05f91fdff3d7ff0746c87508868424fn/a 
2022-03-10n/aexe dd332eaa29f31b1ab7066a231fc87376208766088f5c43c7f19ed41c51439cfan/a RedLineStealer
2022-03-03n/aexe 27d036f15d9417dfdf51c68bc069a1609b7a07ae071641eb1448b6e82da03been/a RedLineStealer
2022-03-03n/aexe b08244867b687e32aa1690f2456f751c3d8f09491f68fca5215b2e30348e0b98Virustotal results 17.14% 
2022-01-17n/aexe 6068f815c1087683fe899f02e8f493fcf7b98197a1373ab865ea1dcb1bbf5be6n/a RedLineStealer
2022-01-14n/aexe 7747f0397ef330b53d0bd68dfe9ed416a935851760657b7df0ed93a7a8a5692cn/a RedLineStealer
2021-12-30n/aexe e670a645b65e5a4deadb6d555fa4f2bc88ef92a5e9657419f410bd1cc076f407n/a RedLineStealer
2021-12-28n/aexe 3d07b3a6481876dc40a8e3af264d7a9c94fcbec993d893670ab28d92f1fb8383n/a RedLineStealer
2021-12-22n/aexe 121491f922bd0ee98457256173760d0a48781eec8096013c410f144ef34de3cdn/a RedLineStealer
2021-12-08n/aexe e1d1e1e5d58791a2736341d2c78448231151b92ceb4b17d1c056a6da9f425535Virustotal results 25.76% 
2021-12-07n/aexe a9c68b448101f65cb3cc37b23ec5f9a3ca49bcbfc5bb81b2387524f71be57bd1n/aRedLineStealer