URLhaus Database

You are currently viewing the URLhaus database entry for http://91.213.50.36/files/hamburger.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2446783
URL: http://91.213.50.36/files/hamburger.exe
URL Status:Offline
Host: 91.213.50.36
Date added:2022-12-05 19:50:07 UTC
Last online:2022-12-07 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-12-05 19:51:07 UTC to abuse{at}rentaserv[dot]su)
Takedown time:1 day, 21 hours, 32 minutes Poor (down since 2022-12-07 17:23:35 UTC)
Tags:dropby PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-07n/aexe fad1b92b67d6509a5d114b43395bd428b8fff6b827198083f1abc801a9c78525n/a
2022-12-07n/aexe bb6afd25daa350615afc7d47f8fd85ce5fd1175da59fd17210fb478fdbef4b7fn/a
2022-12-06n/aexe 99cb9ea998d774a077d760f6a767660a520bc882a73195b3cd0282c2e967fb13n/aRedLineStealer
2022-12-06n/aexe 5866f921e4e7d2eef8693f9fefb19ccd46224c02bb46dd51639d8680de185a40n/aRedLineStealer
2022-12-06n/aexe bc376ec9587207d00b9af28189d47c0341a430c93167b732be851a0725f4a37fn/aRedLineStealer
2022-12-06n/aexe 089a7558a065052eccbaa9f3f734d4d1b5066bf2bb06fc9eef58104644e9bc3cn/a
2022-12-06n/aexe 6e36d2c22f1896776a95909efa624b7ea6f2219e543c0c0db4d1cd155d393e54n/a
2022-12-05n/aexe 3c17013b321895f72a5aa301831a7dcef8538ea75e166e8111272b22949a91c6n/a
2022-12-05n/aexe 707b217b7f9348730d740b5e0bdb03d451cb24250f423605feb3a8993c915626Virustotal results 19.72%
2022-12-05n/aexe 67735110d805d3ac6adfbbfb2cdaffa711aa3f29733b764998d55ae12c4d21a4n/a