URLhaus Database

You are currently viewing the URLhaus database entry for https://iranparsa-novin.com/TrdngAnr6339.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252484
URL: https://iranparsa-novin.com/TrdngAnr6339.exe
URL Status:Offline
Host: iranparsa-novin.com
Date added:2022-06-29 16:07:06 UTC
Last online:2022-07-06 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-29 16:08:07 UTC to fateh{at}discoverwebidea[dot]com)
Takedown time:6 days, 14 hours, 55 minutes Bad (down since 2022-07-06 07:03:59 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-04n/aexe 358fc61235ec7b1c4eb2c26716ca7cbb19bca7de64f5044d485fdfa1cefa2356n/a 
2022-07-01n/aexe aa5fb814e1c232a124b35816e95b91e55c6b8b9ca1ce654b9104702316e292c1n/aRedLineStealer
2022-07-01n/aexe 930a97743fc8357d6db183c5692941bebf905b9df0ac57367ea48571e3b2ac62n/a 
2022-07-01n/aexe 76d702e4a9cd38585e4eb05074b10f123a8f16054d6dda66e6a2b1853de85c69n/aRedLineStealer
2022-06-30n/aexe 30ca0bb574790dc4fb32320810a2b2446eed0f5fc5d31629ea3b47b3892db6can/a 
2022-06-30n/aexe 274ae0f50b77062853230b8a0c90e12ac49951301e31b1f5fa5edcf14c4bfe09n/aRedLineStealer
2022-06-29n/aexe 1bdaf6e7454d17ae8d8d39f8c2e3e8efddab6713e6759ca166887a6e183a8d88Virustotal results 14.71%RedLineStealer