URLhaus Database

You are currently viewing the URLhaus database entry for http://45.138.74.104/cdn/cn.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2275333
URL: http://45.138.74.104/cdn/cn.exe
URL Status:Offline
Host: 45.138.74.104
Date added:2022-08-21 14:53:02 UTC
Last online:2022-08-22 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-21 14:54:05 UTC to abuse{at}aeza[dot]net)
Takedown time:12 hours, 0 minutes Good (down since 2022-08-22 02:54:39 UTC)
Tags:exe opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-22n/aexe 974e0c1a83b80f6d1d7e5c2848edc5c544d407f3dbd4fe7fdcbc20a3dae306e6n/aRedLineStealer
2022-08-22n/aexe 47e16a5cbdfab1b3a9e74f85c50dc5c5a1cd4c4b8806d9cb566a460e23c95ba7n/aRedLineStealer
2022-08-21n/aexe 18dcb0571983f250cbf8df1089c1a554466416887a43c3a3741c4bef2befdad1n/aRedLineStealer
2022-08-21n/aexe a33279bb3a304cc7e9dd989d9391e920d40bbdd947abdc49d05406ef77bacb19n/aRedLineStealer
2022-08-21n/aexe e81d45f32569cc7a61bca45e56a4a53abebb77b8809da6d14ff35eb1749650d0n/aRedLineStealer
2022-08-21n/aexe d02a181ba86775317a7c4a1da165b94b50f37f8b725ff93caac2398df95a799dn/aRedLineStealer
2022-08-21n/aexe 0eb05abe0d7296e9af6517c6c5c4327962b7a4373a5ba3706e2a08c6b3f4030eVirustotal results 35.71%RedLineStealer
2022-08-21n/aexe 0c2137434ea4ab5b5a744455ef1f773ac1ba28720ad722b010e1cd2e84647835n/a RedLineStealer