URLhaus Database

You are currently viewing the URLhaus database entry for http://91.212.166.17/MicrosoftKey.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2382077
URL: http://91.212.166.17/MicrosoftKey.exe
URL Status:Offline
Host: 91.212.166.17
Date added:2022-10-24 06:34:05 UTC
Last online:2022-10-24 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-10-24 06:35:13 UTC to abuse{at}rentaserv[dot]su)
Takedown time:14 hours, 17 minutes Good (down since 2022-10-24 20:53:07 UTC)
Tags:dropby PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-24n/aexe b62ebe6b28b02ae9092ced023b76e8a1ff48798025c93f40548db508035d1962n/aRedLineStealer
2022-10-24n/aexe 489529112a5723a8a10721cd849c7c1ac08be57025b069b585a769d78ff26ea2n/aRedLineStealer
2022-10-24n/aexe 32e3a90268a245c20daf420e7e50521b8501a8c1b2e15b79a6938688ac80eaa6n/aRedLineStealer
2022-10-24n/aexe 69a9e8239fde88fef3b3fb4d92220390f9c9f84f8c3964678eeab3fbdbd49dbcn/aRedLineStealer
2022-10-24n/aexe f6826dbd4674d710f36a8d66991239c84958591feb9e1ef03b8393c38659d9e2n/aRedLineStealer
2022-10-24n/aexe 809b0a9b896b9abcb0d1fd2cfbf61ad280c04ab801123aca803ba1cbdc6c42a6n/aRedLineStealer
2022-10-24n/aexe 6eb0af96065d646ab24c8863032d95e24321b2ccffa9d8b759914237cb439f96n/aRedLineStealer
2022-10-24n/aexe de40f288db5205260851385815e74116dbaf8d392a8c482ad9d89aa653dfed2an/aRedLineStealer
2022-10-24n/aexe 08a013750c3ed9e339bd3648d917d2d4b6e9abe21cc1ee36cdc93a136bd5280cVirustotal results 39.44%RedLineStealer
2022-10-24n/aexe b4447a4391e46c6a2aa54352e24ffaa942cb5fed36c93200ca797c8aed010113n/aRedLineStealer