URLhaus Database

You are currently viewing the URLhaus database entry for https://theforensicinsight.org/zormion.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2312782
URL: https://theforensicinsight.org/zormion.exe
URL Status:Offline
Host: theforensicinsight.org
Date added:2022-09-24 11:19:06 UTC
Last online:2022-10-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: tcains1
Abuse complaint sent (?): Yes (2022-09-24 11:20:08 UTC to abuse{at}hostinger[dot]com)
Takedown time:8 days, 10 hours, 36 minutes Bad (down since 2022-10-02 21:57:03 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-26n/aexe dcc8fd01eea05511d4f27061c29e66a7a6996cf5f116edf57592b8c9281d9d65n/a RedLineStealer
2022-09-26n/aexe 4fcca03bcaa0a7503d169479b9f0fc878fd193fb366b44700a6103b7f5c5075dn/a RedLineStealer
2022-09-25n/aexe fd3338be6aa05e44e93bb1ed931afb6721df35377d94a56c137d3e7d25cf6e5en/a RedLineStealer
2022-09-25n/aexe 020cf8b9115930cffe959c11ec83f7c10cc31e051003b0ef2e25ee1c40d5ecb0n/a RedLineStealer
2022-09-25n/aexe 6461566a91332acdada09a95d7fb9d8e6f37408281c360276dc8e094657888acn/a RedLineStealer
2022-09-25n/aexe 775f7f9041236757b05676318037000e221a582bdfd161b89a11a19fc4fde73cn/a RedLineStealer
2022-09-25n/aexe 5bf16a50e76443746ef25fdd8f72f8e78dca9becd4ed2c298046c9b11c2655cen/a RedLineStealer
2022-09-24n/aexe 8fe0766e52fe6f05622654a41ea8b33fca6c5251fd659eb4cc126a3059b1513dn/a RedLineStealer
2022-09-24n/aexe 47f8240868925144424daa64d60e34acd965fbf73aad16f35cb04ce9d31117d4n/a RedLineStealer
2022-09-24n/aexe 7dccf0c0d5215a5bcacd17f7b8e57ee36733d962e8430b6b5e135d4ea96f51e1n/aRedLineStealer
2022-09-24n/aexe 53307de2ad77233e82687f446422deee438582d87d190921e7a5c8d8d949f0acVirustotal results 42.03% RedLineStealer