URLhaus Database

You are currently viewing the URLhaus database entry for https://theforensicinsight.org/james.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2313237
URL: https://theforensicinsight.org/james.exe
URL Status:Offline
Host: theforensicinsight.org
Date added:2022-09-25 05:10:05 UTC
Last online:2022-10-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-09-25 05:11:05 UTC to abuse{at}hostinger[dot]com)
Takedown time:7 days, 15 hours, 54 minutes Bad (down since 2022-10-02 21:05:44 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-26n/aexe d4affbcba011f3eeefc966199aa28089f3c00438511798e5b2da5bc90b9ebba1n/a RedLineStealer
2022-09-26n/aexe 5f084905beab026985379a52ab06f97a1f12b6f3e884a91654c00635e51bf672n/a RedLineStealer
2022-09-25n/aexe acf39a2741293a55e76c452ba92e87a1ed986eb6071a7bede3eda179f0c132c1n/a RedLineStealer
2022-09-25n/aexe 07c7e4b67df083d4e0c655fa6641ac382de3ef6cc6eca02a16de60130ec262a1n/a RedLineStealer
2022-09-25n/aexe 98cae56a5b3fde47c5436a62b62fb4ae2654ec59d39607faf741e3f9e298dae4n/a RedLineStealer
2022-09-25n/aexe 9f8ed5976f0221e19b5a8edd4127fb72a17b2d37be6fe8e9f5e0b8761c05349dn/aRedLineStealer
2022-09-25n/aexe 5d72a91ee3aeab2a634e8023b2c0530c8429f1151f1e29421ff7a16cec75617dVirustotal results 43.66%RedLineStealer