URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.24.244/TPB-2-Links/TPB-1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2550873
URL: http://95.214.24.244/TPB-2-Links/TPB-1.exe
URL Status:Offline
Host: 95.214.24.244
Date added:2023-02-26 06:36:06 UTC
Last online:2023-10-31 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-26 06:37:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:8 months, 7 days, 12 hours, 27 minutes Bad (down since 2023-10-31 19:04:46 UTC)
Tags:RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-22n/aexe bb08e330702eccd5a5cd5f69a6ab725687324b6274381e5ad5c6abc0f78d5606n/a RecordBreaker
2023-08-22n/aexe 66e3a760eae179ef8183f0e9df0d39b0162a62cd2b377d5c0fd54bc4d59c48fdn/a RecordBreaker
2023-07-20n/aexe a966cedd464a05cf86a0f3c6d4b3e5f6d1a3c430fa0658fab350517f24dca4a6n/a RecordBreaker
2023-07-06n/aexe 9d05e8ef93511f02e7f0d270402b37658817a2d233f9cd12b40b87d4a4af7a77n/aRecordBreaker
2023-06-21n/aexe b98c25c9332c08071cdce0e2076000fc1c918b058af7bfd572724b1e86f8ecb5Virustotal results 44.93%RecordBreaker
2023-06-11n/aexe 1ac42cdcfe4c50559ecbd39d0626bfaaa569b6b92f28ac38eaa3d063d910c806n/a RedLineStealer
2023-02-26n/aexe 7304e4710381b20058acc561ff7a36df7e2ce614e8d8e045452bbfaec9f1ab6eVirustotal results 84.29%RedLineStealer