URLhaus Database

You are currently viewing the URLhaus database entry for https://paint-regen.club/Golleg_crypted2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1942361
URL: https://paint-regen.club/Golleg_crypted2.exe
URL Status:Offline
Host: paint-regen.club
Date added:2022-01-02 00:20:14 UTC
Last online:2022-01-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-02 00:25:02 UTC to abuse{at}cloudflare[dot]com)
Takedown time:4 months, 3 days, 11 hours, 16 minutes Bad (down since 2022-05-05 11:41:43 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-02n/aexe c970640df76c945c79b84cf55c1ec0ffed3cfba2e5d3c587b54b886aae6a0c25n/a
2022-02-28n/aexe 1d9c0ade1e2c9bbffb008704c181f404dd270d094c9e3349dc4d28b1da7f90d0n/a 
2022-02-27n/aexe 84c12a599b34cbb7be4d5f491d4f67d5cea04a3adb28655aa9fb77b761a8a638n/a
2022-02-26n/aexe d5868b42cada873674caf299c6e5dc614957dc49dc7f3ffb312d3dd0374314ben/a
2022-02-14n/aexe 01ce496e53ddf9dacd4f7781f7162d20f4dcaf5095a3c42a4325039fe0d146d0n/a
2022-02-11n/aexe 7057d3a37ba472e8991a2b77c92b1d3bcc485e84f5e6a3a88ebf90092148b00an/a
2022-01-02n/aexe e967df04096f4c1c9823a89657f33d2af95acf57d8a1fa0cc92c91b2c6706fa7Virustotal results 52.94%RedLineStealer