URLhaus Database

You are currently viewing the URLhaus database entry for http://zonasertaneja.com.br/5/data64_4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2117687
URL: http://zonasertaneja.com.br/5/data64_4.exe
URL Status:Offline
Host: zonasertaneja.com.br
Date added:2022-03-28 18:17:06 UTC
Last online:2022-04-05 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 18:18:17 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:7 days, 23 hours, 43 minutes Bad (down since 2022-04-05 18:01:19 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-05n/aexe 4c96f44d0d82cc20b858dfa38f6a11f504a7f5d26485f0d3ca8d30d795672500n/a RedLineStealer
2022-04-04n/aexe 3f9d357601ac5cad05ffcbabe319011bfa4e7be1bd9dd7e2f87fb759e0df1591n/a RedLineStealer
2022-04-03n/aexe 0b882ab6578a2d25adfe0eac5b27c7ab77b72675fadf28983558d20ff218397fn/a RedLineStealer
2022-04-02n/aexe 03deb53a392fe0041d5c06bc510e0464ad81d6d30b01d678487a35f7d30831c4n/a 
2022-04-01n/aexe a3b1ba80a85e48b136560d2e7794b6d16d391944d7ef15c4acab9a8f324d5fc2n/aRedLineStealer
2022-03-31n/aexe 4f331f088dcf5cf92212ce3f731932ce60e219db2e370bd85cea6e296fccd836n/a RedLineStealer
2022-03-30n/aexe a6d2e5d7b0e466716c79397d044f982bb7cd77b029cb210d3611b22f5accd4b0n/a RedLineStealer
2022-03-29n/aexe e7e94d6ed84c46916e428e3af60dd75c24fe12b4dda159f73eaccb8c9fcd0874n/a RedLineStealer
2022-03-28n/aexe 4504376c4ddef9e7d2cf767917c9718a99bba4998c982eb1354c7cf99e9d5bc3n/aRedLineStealer