URLhaus Database

You are currently viewing the URLhaus database entry for http://zonasertaneja.com.br/5/data64_1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2117679
URL: http://zonasertaneja.com.br/5/data64_1.exe
URL Status:Offline
Host: zonasertaneja.com.br
Date added:2022-03-28 18:17:04 UTC
Last online:2022-04-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 22:29:07 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:7 days, 19 hours, 7 minutes Bad (down since 2022-04-05 17:36:24 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-05n/aexe c96056619ad75f12f91477250b953ed1ecd952c8117d529bd44c637e31e00271Virustotal results 21.74% 
2022-04-04n/aexe cd33d0651c6412c37f3b86c6c0cec9dc8956b2c9c2683579f1a2934492daf701Virustotal results 23.19% 
2022-04-03n/aexe ebccec79dade98b555e165fc883e7832fb86a1178e5c9ef807a947a9ce8141den/aRedLineStealer
2022-04-02n/aexe eb5b3b27c24c47a532fb0cd4778e74e75a6548d21f06d7a37ea5de862b2a0443n/a 
2022-04-01n/aexe 53bd1595603be2c0069df8a71f2316bf2402a25938e5c359991465e0e9292808Virustotal results 25.37% 
2022-03-31n/aexe 677433f2326c92d7e0d30a25d3673990e7b8fca5e03cb9ee759fc969794261een/a RedLineStealer
2022-03-30n/aexe e9890c5e84f4a11617ee00ae8d359221f20161bb8d7ae4279c7b6dff6d13ad8dVirustotal results 41.18% 
2022-03-29n/aexe 35ca9c06c64525702c430b2781dca9570ba31ba755294b034b926357a2aa2451n/aRedLineStealer
2022-03-28n/aexe 3ed09132d1da26eca39b4584e8207eefc332670ff897f2e933a46c0ac98ba926n/aRedLineStealer