URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.24.244/HEXO-CLIENTS/Rljanzfv-1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2314896
URL: http://95.214.24.244/HEXO-CLIENTS/Rljanzfv-1.exe
URL Status:Offline
Host: 95.214.24.244
Date added:2022-09-27 04:36:05 UTC
Last online:2023-10-31 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-09-27 04:37:06 UTC to mayakconsulting1{at}gmail[dot]com)
Takedown time:1 year, 1 month, 9 days, 14 hours, 35 minutes Bad (down since 2023-10-31 19:12:26 UTC)
Tags:32 exe RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-05n/aexe 36dc266ad1ea8df01393368710ee6c6fd21629e833252cf0f3f63dffd908c805n/aRecordBreaker
2023-06-21n/aexe b98c25c9332c08071cdce0e2076000fc1c918b058af7bfd572724b1e86f8ecb5Virustotal results 44.93%RecordBreaker
2023-02-03n/aexe 650ada27b894204248d0af32365b2f400e4a19244293ef54c439d2c54345449en/aRedLineStealer
2023-01-24n/aexe e23bfe5194880ddc3c65cd67adc2851abc2d51a547207fd558631d5e9b6227cbn/a RedLineStealer
2022-09-27n/aexe b1d0054cc04e1f882313bfe5ecbcae1dc58245267311cf1eafa8f3d531687dbaVirustotal results 48.61%RedLineStealer