URLhaus Database

You are currently viewing the URLhaus database entry for http://45.155.204.13/cryp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2553980
URL: http://45.155.204.13/cryp.exe
URL Status:Offline
Host: 45.155.204.13
Date added:2023-03-01 06:37:10 UTC
Last online:2023-03-01 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-03-01 06:38:05 UTC to abuse{at}rentaserv[dot]su)
Takedown time:11 hours, 31 minutes Good (down since 2023-03-01 18:09:24 UTC)
Tags:dropped-by-PrivateLoader RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-01n/aexe 2dd85e747e3fff1beb991efd7fe17508bdf59b7a435edb032149c582171d7a72n/a RedLineStealer
2023-03-01n/aexe e2a1a4867efc447795ba9589441fd463a98140f1a63cad8bdbc41918d0b4f5b0n/aRedLineStealer
2023-03-01n/aexe 948a2a18460d7282a8079f762a0de2e61cbfef340f2e48ad71d7290c31f86afan/aRedLineStealer
2023-03-01n/aexe 249001c4665a36ed5bc52b207cd637a3c10f53cf1844eb39dca8dbef693040cfn/a RedLineStealer
2023-03-01n/aexe c2348da208353e096df8a9b8be2029c434959abdfb3a8fee2e82e5742b87de68n/aRedLineStealer
2023-03-01n/aexe 41e4b903ce4dcf1e0a138ce1edb1280d6fe2b50a222c925d3600903c4eb2fae2n/aRedLineStealer
2023-03-01n/aexe b0d58abdf40c6e922ecad36224a0c65bc3f87fcd36c781566f5d7733b72e608bVirustotal results 30.43%RedLineStealer
2023-03-01n/aexe 12d20e3f42efc0389d10c3ec021d226228104ab6d12ccc3506fd10372f2e097cn/aRedLineStealer