URLhaus Database

You are currently viewing the URLhaus database entry for http://45.138.74.104/cdn/3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2275303
URL: http://45.138.74.104/cdn/3.exe
URL Status:Offline
Host: 45.138.74.104
Date added:2022-08-21 12:50:05 UTC
Last online:2022-08-22 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-21 12:51:05 UTC to abuse{at}aeza[dot]net)
Takedown time:14 hours, 2 minutes Good (down since 2022-08-22 02:53:18 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-22n/aexe b1f6c920fba5a9564730d9949adf20436f3440a9d4e2378089ebba5ef4991f76n/aRedLineStealer
2022-08-22n/aexe e9c290333544f63a704664d343fdcf8e67b35be5459c3aef6f8fd8bbb431adf6n/aRedLineStealer
2022-08-21n/aexe f8fa2bcb6867c88c35c86bb5fef4c5aa7d15698e820e6ed7451566e2a5269815n/aRedLineStealer
2022-08-21n/aexe 22e252bf71d4cb3e8da3af59d3a2bc7b1052aec2779b56e09d504c50564365efn/aRedLineStealer
2022-08-21n/aexe 008837e6d7d4baa68f0a33f54a15274f16764e7ac343863a4b1099b581d4f861n/aRedLineStealer
2022-08-21n/aexe b0f3081c658a02b13e9a0b43632193aa15186a21bac085223e36c1a5e98ae81fn/aRedLineStealer
2022-08-21n/aexe 11345d326056af1fee9c911a3b99e9eacb4d323924dafd6f1a85a4b7e9e7f526Virustotal results 30.00% RedLineStealer
2022-08-21n/aexe 95ab4a5a3ae820d60fa7d3a4e1cf47b5c98ffeabab390da423b84da23a5139e7Virustotal results 23.94%RedLineStealer