URLhaus Database

You are currently viewing the URLhaus database entry for http://downshiftingrace.top/work/top.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1933508
URL: http://downshiftingrace.top/work/top.exe
URL Status:Offline
Host: downshiftingrace.top
Date added:2021-12-29 16:47:16 UTC
Last online:2021-12-31 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-30 06:46:55 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:24 days, 3 hours, 47 minutes Bad (down since 2022-01-22 20:39:11 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20n/aexe 2212ce4054b2aeab80ba5b593ac8fe7d86da414564665dad2c2a6275b1a62c06n/a RedLineStealer
2022-01-19n/aexe 673713340b48e95efee5a2b576260ee3a97524c173b877aaa7e7b4bdf4c39706n/a RedLineStealer
2022-01-18n/aexe 0c3ee2b5b2b86e801df648a6b40ea26d55d976c31c8d4c6e0207bc03abc35148n/a RedLineStealer
2022-01-17n/aexe 96c3b54cfc2d6ce01e399b24ef7f17df1ad61f0b365a075606a42fa6cdcfa954n/a RedLineStealer
2022-01-16n/aexe 0c7a287dceb001509f8004fe1b339537563169ae38ab2a147a4ca36ebf1c37a7n/aRedLineStealer
2022-01-15n/aexe 44e4a5195de62e1fd8bf6d15132f76c75661f8d6e9fbd009b5319447d1a35033n/a RedLineStealer
2022-01-14n/aexe c6dd666cb61fc28ecb6d89d501598faae836c0c6ab5ca2be9de597d43170eb65n/a RedLineStealer
2022-01-13n/aexe 1a87f4fd91fedfd1f5eaf9b8973d3253f3ec24f0f95971eedec1dd65aaaddfa9n/a RedLineStealer
2022-01-12n/aexe ebb896a815d07015e1447c75ce4e9499e8e2ccbca9bb714d4010169b1c8adf1en/a RedLineStealer
2022-01-11n/aexe 2b53c75dbedbf612e5d9a22d2e7a21a0ad7357ef222c257be375eafe61456d44n/a RedLineStealer
2022-01-10n/aexe 293df0d904ebeef9de8ac2c3dadf6c31dd5fc10b19002f5c71f9a10c74f2107cn/a RedLineStealer
2022-01-09n/aexe 955cc74a30048b6077e95c3f6e8e70a7cd397c724477dfa2268659437da6ce5bn/a RedLineStealer
2022-01-08n/aexe 8bc0b141dd308ba9197709c12b2c4d372beaed023de7c47edccdd5977b9498a8Virustotal results 37.31% RedLineStealer
2022-01-08n/aexe 0224632fb43386d7d981b9635129d2fade6f3a191e11f49521242862f08a9751n/a RedLineStealer
2022-01-08n/aexe 8617cc60a5231c3f4259bbe544ec723813e33d3b8a71f09bf6a03c5a343ad72dn/a RedLineStealer
2022-01-04n/aexe 882d939156f3bc35225150adb988a631d481c8c6c634413406310ba7c147fe2an/a RedLineStealer
2022-01-03n/aexe b38304de2bacd21ac6a382ad10eadc07d14290d653676f4246b5f208637ca9f6n/a RedLineStealer
2022-01-02n/aexe 8d5ed9efa77109eb91c78908c4e8e5fa2d60b82a2c3ff11dc42aa2432a0a48dan/a RedLineStealer
2022-01-01n/aexe 284e54e2586278aa57a1a00d238fbb1727205088bd85c7b2e86761db4410e235n/a RedLineStealer
2021-12-30n/aexe acf6d9a4a584da950a20325d843cd546ee349584cecdc021b53658e1c25ae9f1n/a RedLineStealer
2021-12-29n/aexe 7cd9b7f895492a6e4e9cd681b25cec80e0a3f95f2ca2717dc91b5fd45fef552dn/a RedLineStealer
2021-12-29n/aexe ee23f4d44cf618e05d480cb1dc2c7db45a64e1d9bad45d98412b6981e576d661Virustotal results 70.15%RedLineStealer