URLhaus Database

You are currently viewing the URLhaus database entry for http://64.44.102.248/sdtraff.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2260294
URL: http://64.44.102.248/sdtraff.exe
URL Status:Offline
Host: 64.44.102.248
Date added:2022-07-23 02:13:08 UTC
Last online:2022-07-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-23 02:14:04 UTC to abuse-reports{at}cloudzy[dot]com)
Takedown time:7 hours, 3 minutes Good (down since 2022-07-23 09:17:20 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-23n/aexe 1f79324450ecd1494519a2ba2942903c78ade8d9021b2cae61dc17258cd61724n/aRedLineStealer
2022-07-23n/aexe b7493886c96a0d42ee0baf4601f4d3a2a41df86bbea9c7725b2b3f065b33ca74n/aRedLineStealer
2022-07-23n/aexe ed54aef6dce561f10f03ace4580330719a5c4482e6b46ec9cd1c0a8464696515n/aRedLineStealer
2022-07-23n/aexe 15a742e0f321fd649d5ffeea0940a554c5ad6c6ca400ac238fb282ccb166d565n/aRedLineStealer
2022-07-23n/aexe e6389e05edf0eafd2330af2d40b0fc220babc1f4a0e827b46d71d5aeb3acc1f3n/aRedLineStealer
2022-07-23n/aexe 6fd61d0a20a7c1fbc2ff4243792a632a6de93e9aeaecd9bd88138a660f714b31n/aRedLineStealer
2022-07-23n/aexe 33b95b050eeebdf0dbce9a16c8bf7d99a4a6fbe66c17e5c725dbb69d95fcf4c4n/aRedLineStealer
2022-07-23n/aexe 26fdf86fcee152ef6eb64db3ab973aa49d6f3ff7c840edea54c865dc3e6af72bVirustotal results 49.30%RedLineStealer
2022-07-23n/aexe 35c6424237094789bfb86f3853b68e11f70c9c5de53e4a39abdf581c562adcbaVirustotal results 49.30%RedLineStealer