URLhaus Database

You are currently viewing the URLhaus database entry for http://193.142.59.172/forum/img/sefile.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2532821
URL: http://193.142.59.172/forum/img/sefile.exe
URL Status:Offline
Host: 193.142.59.172
Date added:2023-02-07 08:24:09 UTC
Last online:2023-02-16 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-07 08:25:07 UTC to abuse{at}hostshield[dot]net)
Takedown time:9 days, 13 hours, 20 minutes Bad (down since 2023-02-16 21:45:40 UTC)
Tags:exe RedLineStealer link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-11n/aexe 2f2f173ced72fa085b0b6a5a527a0f2024691e9ceea58605e783259b5828dfe4Virustotal results 39.44%Vidar
2023-02-08n/aexe 4f13a5f7625fb7ae7adfcd9ac4b44fa453a319372ee92838a019516218167108n/a 
2023-02-07n/aexe 0e8849fae3014fbbf9e1c4e72d1022b8887665eadc0bc019860e2e90d7c7b146n/aRedLineStealer
2023-02-07n/aexe 185b2dbe84c19c5c318bf241c19c07ee07202015dfbc6611b324ca45448982d8n/a RedLineStealer
2023-02-07n/aexe 5779a83a8d2b1823ad7b44c37390cb6997fa66762e2a6b74d81b8faa559ece0bn/a RedLineStealer
2023-02-07n/aexe 8faf2d0e248c0775f91d534325ad36c730f45e3e2717752d12fc5eb99dff6110n/aRedLineStealer
2023-02-07n/aexe a25b135d763bacff28c4c6f0a1dda204e66d3924ef8e4305015600020a1b93b2n/a RedLineStealer
2023-02-07n/aexe 282ed78f108bb24e9afb63f9253b8d771eed91b2a6b3089de94a84ee0928d6f0n/aRedLineStealer
2023-02-07n/aexe 55d930de42a7b77be3ce4fc6c7750f9554aeec874b883ea43e7a5dc6fd97e5b9Virustotal results 37.14%RedLineStealer
2023-02-07n/aexe 35cd53ed6908463b7904ce70f1a278f10ecc0d6517897624e3656091dab5f0cbVirustotal results 37.14%RedLineStealer