URLhaus Database

You are currently viewing the URLhaus database entry for https://cemageng.com.br/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2480496
URL: https://cemageng.com.br/2.exe
URL Status:Offline
Host: cemageng.com.br
Date added:2022-12-22 18:56:11 UTC
Last online:2023-08-07 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-12-22 18:57:15 UTC to abuse{at}bluehost[dot]com)
Takedown time:7 months, 17 days, 18 hours, 11 minutes Bad (down since 2023-08-07 13:08:36 UTC)
Tags:drop-by-malware PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-24n/aexe f863b2eaafe78bd61faf02eda91f00fafe397b7accd0817f03ce68a355d625f4n/aRedLineStealer
2022-12-24n/aexe 5b7fd8399f4d782bb4f08df3f4a04b3f580c8b64659c0de4c353b2c01bdb3db0n/aRedLineStealer
2022-12-24n/aexe 03ca2aaa9e5bbe7728bb69be32b347a12178e6376d5efbb7a7b0a228b70e5dcdn/aRedLineStealer
2022-12-24n/aexe 0114dbb79d1d15790f5615ef5b0db690d50b4f90b82f125ca5ba5cfd64a65bdfn/a RedLineStealer
2022-12-23n/aexe a943cf4015c9f16552c0530f19c462c014f7ed73b09406c81366a28e69361462n/a RedLineStealer
2022-12-23n/aexe 38e053367d95e49cde1ecefdfa83958bdd155b9c175e203b803f26436acb5e53Virustotal results 33.33% RedLineStealer
2022-12-23n/aexe ea05f9e9089662a6a8092c18b71ae0a41fcc3a5785623eb596586a0b9c1e76bbn/a RedLineStealer
2022-12-23n/aexe 67e4695c0a0061f07664c7bdc0f2d07d8af8aa912123d791cb55a551cc193b3cn/aRedLineStealer
2022-12-23n/aexe eef8190b6cb1e67b8490ffd34efec70c744eeff79367b288447256d6ad82b18bn/aRedLineStealer
2022-12-23n/aexe 01320b475214dbdfa7782958986b96dfadedbf5d27c708ab3616d3cdf1be9b34n/aRedLineStealer
2022-12-22n/aexe 42c07c82e3328b7d7a4e9804ba3d558a64c0e8a2ce018e9a5f7155a9792d5376n/aRedLineStealer
2022-12-22n/aexe 67d787249ae186a7000e4db614af862c22db210fa263d2bdac3dcc7b06db8665n/aRedLineStealer