URLhaus Database

You are currently viewing the URLhaus database entry for http://85.209.135.181/files/File.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2452784
URL: http://85.209.135.181/files/File.exe
URL Status:Offline
Host: 85.209.135.181
Date added:2022-12-09 20:52:04 UTC
Last online:2022-12-27 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-12-09 20:53:05 UTC to abuse{at}des[dot]capital)
Takedown time:17 days, 14 hours, 59 minutes Bad (down since 2022-12-27 11:52:24 UTC)
Tags:dropped-by-amadey LgoogLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-14n/aexe f1cd87c944d9650c89a51bde24774850f087f6fdb6da5eba6cd360d79b98fc5cn/aLgoogLoader
2022-12-13n/aexe 0d4089a9c33b6e2fbe05823f34c4c1bd1247a3438d9e0e5727a3aaf135accbacn/aLgoogLoader
2022-12-13n/aexe 5dcf48fef44cefbf3f972e1ac477539776bfe41cbd29801bae6e254dbe12dc13n/aLgoogLoader
2022-12-13n/aexe a99c69752668a94268cdb482df74649d755fcf56ecd9f431b1cb03b816a593ccVirustotal results 25.00%LgoogLoader
2022-12-12n/aexe 51bca1340951634cd5bdb488290a162c521945fb0cf52c360b9420c8a3cfd9e4n/aLgoogLoader
2022-12-12n/aexe 1dae118fba4e42dbbe22e6f8b3deba26ad7a77b628c1a71e19bf5e47c01bc23an/aLgoogLoader
2022-12-11n/aexe 45823c5ed289f2ceb30eb5324fd1e7e6b782806ac33188cf98b79ecb42e35648Virustotal results 16.90%LgoogLoader
2022-12-11n/aexe 9fcfabcd0c27fcac7717f38c65c99a42fce5e325e85488248a351f1d4041f691n/aLgoogLoader
2022-12-10n/aexe b6d11912ccaa3ef1bc9886e58bac7d31db936a4964d115469dee958ad266bcc7Virustotal results 12.68%LgoogLoader
2022-12-10n/aexe 81ccc0f350bb406db3c59e2957b99f6d3a6f587f1d9b00b66dbf97f9a5215615n/a 
2022-12-09n/aexe cae45a48ed911a6b09c3d948019146afe2f1f0c97c07703e067d954d73281f45Virustotal results 27.14%RedLineStealer
2022-12-09n/aexe 0f29980289eacdd47e00aa7db587bfdf460988dc7d0c502bc74814a6a545d735n/a