URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.24.244/newz2k/Z2K-1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2550872
URL: http://95.214.24.244/newz2k/Z2K-1.exe
URL Status:Offline
Host: 95.214.24.244
Date added:2023-02-26 06:36:06 UTC
Last online:2023-10-31 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-26 06:37:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:8 months, 7 days, 12 hours, 28 minutes Bad (down since 2023-10-31 19:05:29 UTC)
Tags:RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-22n/aexe f00b2b25861c0218820c23eca788881bc73c8470f59872989acf60c04cd83630n/a RecordBreaker
2023-08-22n/aexe b655ddde5c881f4f0f661e64c32765dab777adb6eb2ff557d67f35da1738356bVirustotal results 42.42% RecordBreaker
2023-07-05n/aexe 36dc266ad1ea8df01393368710ee6c6fd21629e833252cf0f3f63dffd908c805n/aRecordBreaker
2023-06-21n/aexe b98c25c9332c08071cdce0e2076000fc1c918b058af7bfd572724b1e86f8ecb5Virustotal results 44.93%RecordBreaker
2023-06-11n/aexe 8b1cc654137ba48a02b726637867607fa13cb0b915b77ad185f3f1ff3580d112n/a RedLineStealer
2023-02-26n/aexe 31e477a3732cf4d377bbb89c5a5a3763dadd3581ce07534bb4fc54efb951823bVirustotal results 55.07%RedLineStealer