URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.24.244/1337/TORRENTOLD-1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2505187
URL: http://95.214.24.244/1337/TORRENTOLD-1.exe
URL Status:Offline
Host: 95.214.24.244
Date added:2023-01-12 07:17:05 UTC
Last online:2023-10-31 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: jstrosch
Abuse complaint sent (?): Yes (2023-01-12 07:18:04 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:9 months, 22 days, 11 hours, 43 minutes Bad (down since 2023-10-31 19:01:30 UTC)
Tags:.net exe msil RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-22n/aexe f00b2b25861c0218820c23eca788881bc73c8470f59872989acf60c04cd83630n/a RecordBreaker
2023-08-22n/aexe b655ddde5c881f4f0f661e64c32765dab777adb6eb2ff557d67f35da1738356bn/a RecordBreaker
2023-07-05n/aexe 36dc266ad1ea8df01393368710ee6c6fd21629e833252cf0f3f63dffd908c805n/aRecordBreaker
2023-06-21n/aexe b98c25c9332c08071cdce0e2076000fc1c918b058af7bfd572724b1e86f8ecb5Virustotal results 44.93%RecordBreaker
2023-06-11n/aexe bcadc49beaceeb27068906d6673923c24c12ff73914d6a5ebb66e054565f41fen/a RedLineStealer
2023-02-03n/aexe ebb2dcf0d743e210a391d665b4589e3a0e41189ed1b21fcacc8c14caf13b1ce6n/aRedLineStealer
2023-01-24n/aexe 5fee060bb26c37da4d1205d84d457ed8513e59987a41a0ad094451f4ff14e4d8n/aRedLineStealer
2023-01-12n/aexe c5aad4e5e357257061eeadaed8527c422c4408566da2047ac91250ec5d3d1276Virustotal results 45.07%RedLineStealer