URLhaus Database

You are currently viewing the URLhaus database entry for http://94.131.100.85/s.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2486304
URL: http://94.131.100.85/s.exe
URL Status:Offline
Host: 94.131.100.85
Date added:2022-12-25 16:52:10 UTC
Last online:2022-12-26 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: r3dbU7z
Abuse complaint sent (?): Yes (2022-12-25 16:53:13 UTC to abuse{at}stark-industries[dot]solutions)
Takedown time:21 hours, 11 minutes Good (down since 2022-12-26 14:04:54 UTC)
Tags:exe RaccoonStealer link RecordBreaker link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-26n/aexe 7b5b681c38c257089057651620a683516c25318391a417015769ec273d66dbbdn/aRecordBreaker
2022-12-26n/aexe 353e28e51874a9fe29d93550ce51409afc9b9fb617f46f3686bc0b9075be3e4an/aRecordBreaker
2022-12-26n/aexe e70e3bab6f90e79016bd67a9c934fd9a49100ac5e9a265ee3f5d4f3c1a9ab820n/aRecordBreaker
2022-12-26n/aexe 3cf79fc23f11a3083159b0a8b5b0c04068ccb93715a1f82e360ea31608a300bfn/aRecordBreaker
2022-12-26n/aexe 0f4f28f4e67d88dd5e4fbbad3be608e05d8d157f6ece8f90e68f7423dc5e37c4n/aRecordBreaker
2022-12-25n/aexe 5d8c22a2f979e395dc9f076da46ee96c1b9d0dd266ff59c9bfb71d3353401739n/aRaccoonStealer
2022-12-25n/aexe d91a27a04ac9e4fc3ddfbb37372f0587cb62b8be0ec0cf5afc52a2c4c8ca4ee5n/aRecordBreaker
2022-12-25n/aexe 90abcdb47675972e3ff218c51ea3aacb97b6ca105aed5e1a880704b92177144an/aRecordBreaker
2022-12-25n/aexe 25c17fe456e4f3307e03f8fecb0154fcd4d66374922a4d169b30549f80501958Virustotal results 31.43%RecordBreaker
2022-12-25n/aexe 3e1fbbd273800929e5d4a0d80655a43b262da68eb415141c346b7feb97dc6316n/aRecordBreaker