URLhaus Database

You are currently viewing the URLhaus database entry for http://212.193.30.45/WW/file2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2007754
URL: http://212.193.30.45/WW/file2.exe
URL Status:Offline
Host: 212.193.30.45
Date added:2022-01-26 19:52:06 UTC
Last online:2022-06-20 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-01-26 19:54:06 UTC to abuse{at}des[dot]capital)
Takedown time:4 months, 25 days, 0 hours, 55 minutes Bad (down since 2022-06-20 20:49:07 UTC)
Tags:32 ArkeiStealer link BABADEDA exe RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-20n/aexe fc29c704273818e777995e51c36cecaaaaf57fc5e708786dca85660d30c415ban/a 
2022-06-20n/aexe a6da5c90d33a9a4eb16cd7d56af7b300d4acf17ae935d84f7287ceb17fdfb4a2n/aRedLineStealer
2022-06-15n/aexe 75125ac1b0c97f9826e0d4e261076d3de0a577b586befa5afa53714ffec17a63n/a 
2022-06-15n/aexe 7b9e6e56360155469c3bb8ac68bac7b847a60c1756c884e4df49ed5e8c3e902bn/a 
2022-06-10n/aexe 9bd1bb01d1a9ea2d32afb9811b491f60b09913a5aa19964f8d8c1402cfcc0523Virustotal results 40.00%RedLineStealer
2022-06-08n/aexe 144fd8194046aeed12099dcc19cf205311708629c6a504740852f3a5c27e6a91n/a RedLineStealer
2022-06-02n/aexe c2eb47b6b2412303b7c1b3cf9983d5f3e12c562184a3447491018c44d2d046c0n/a RedLineStealer
2022-05-31n/aexe ca706b38451c6d1d7c4903ba72f8c7f51658c66bb9029b8a5310610c7fa2e803n/a ArkeiStealer
2022-05-31n/aexe 4baf55c196fe562b740907b01f883cd015e484396bb24b6204682f9b0a269d5aVirustotal results 39.39% 
2022-05-28n/aexe 4b51bfdfb096e034e057e4cf48abcdb2f8f3301d3493f286053bf66f9b74f175n/aRedLineStealer
2022-05-27n/aexe dfb47ac5c6506de2784975017ce352e2a0f32b21edf78016b2685ffb5a3036ebVirustotal results 48.53%RedLineStealer
2022-04-27n/aexe 5f381a72c723efe36bc47c96dd05aaf602212fe780edca1894d597c96f76e516Virustotal results 33.82% 
2022-04-26n/aexe 5d07a5560ee417ab4f095dd09570111cd3b63f2292a7aa399df1014b4074e16bn/a 
2022-02-28n/aexe a77e49eb1adee9c570250dc55ab7079d66179aaa6543146d24db42dd8c38a35an/a RedLineStealer
2022-02-28n/aexe a4a574546147449e9b0e5c0bca8a95370d6eaf33bcb0f08b15d59d4731ce37cdn/a RedLineStealer
2022-02-25n/aexe 9e113407979808c9e05887fd0e32925543fca34fe2308ec6484fc97916ef08cdn/aRedLineStealer
2022-02-25n/aexe 0d59f3d28aac3902d48d3bcfcea4fb0657b65c172f2035c3cf05f4226fd11329n/aRaccoonStealer
2022-02-25n/aexe ca2e3443e90f7f13ecef0af86acd93c7cf99eb029b184bff408a9bf196f78077Virustotal results 50.70%RedLineStealer
2022-02-14n/aexe 44122ffd0d5bc851786bf5f698d01e2018657f88072099688844d17f5cd9edf1n/a RedLineStealer
2022-02-10n/aexe b50a488cd0c83c0ebece9fdc48f5bc10631821f59a90b849026400a4d6c99280n/a RaccoonStealer
2022-02-10n/aexe 8ca286f87b1b5d7db67029f00bccd481f0b615c0cebd34da1ca3bfce388bed64n/a RedLineStealer
2022-01-27n/aexe 9760d9e914209b0ee1b44ac47162282be879d5b1e3c867d200d94f53b13b85f7n/aRedLineStealer
2022-01-27n/aexe b27a5ca0a0933895ea686376353fbe6981b8b1af825e3b887f4ca4544d6d6c91Virustotal results 38.81% Babadeda
2022-01-26n/aexe dda97553fa1200283e7c0c206ae794daf00088f59679a2809f45846e3e91601dVirustotal results 41.79%RedLineStealer