URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.24.244/HEXO-SOFTWARE/Sazae-1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2314895
URL: http://95.214.24.244/HEXO-SOFTWARE/Sazae-1.exe
URL Status:Offline
Host: 95.214.24.244
Date added:2022-09-27 04:36:05 UTC
Last online:2023-10-31 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-09-27 04:37:06 UTC to mayakconsulting1{at}gmail[dot]com)
Takedown time:1 year, 1 month, 9 days, 14 hours, 40 minutes Bad (down since 2023-10-31 19:17:35 UTC)
Tags:32 exe RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-05n/aexe 36dc266ad1ea8df01393368710ee6c6fd21629e833252cf0f3f63dffd908c805n/aRecordBreaker
2023-06-21n/aexe b98c25c9332c08071cdce0e2076000fc1c918b058af7bfd572724b1e86f8ecb5Virustotal results 52.17%RecordBreaker
2023-06-11n/aexe 6cd2c786beaa8465fb5c7d16772eddbff0ec333137c2a0b941a05be702ad7361n/a RedLineStealer
2023-02-03n/aexe dce05561ae5582a0a5e716dcd273ed4b9359eb5a2fb556d103c63dc75f03622en/a RedLineStealer
2023-01-24n/aexe 0583d5be3f90408e4009070a24534fa160fcb54ad21e26d9ea6def5079ebee34n/a RedLineStealer
2022-09-27n/aexe 79208f5bcd29a83d75bb073d3f48a483cd51dbd53e9cee5472ab4947a1ede05bVirustotal results 50.00% RedLineStealer