URLhaus Database

You are currently viewing the URLhaus database entry for http://193.233.20.22/male/serko4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2557231
URL: http://193.233.20.22/male/serko4.exe
URL Status:Offline
Host: 193.233.20.22
Date added:2023-03-03 23:44:04 UTC
Last online:2023-03-04 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2023-03-03 23:45:08 UTC to shinomiya[dot]hosting{at}gmail[dot]com)
Takedown time:16 hours, 57 minutes Good (down since 2023-03-04 16:42:21 UTC)
Tags:dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-04n/aexe 14f6df346d1ed9b2cdd5564fee45ddbe775555815c50e9ada5e3658da7f4bdb3n/a RedLineStealer
2023-03-04n/aexe 0143eb12cd48a10ced4206442b4d408e36295a3459b8cf629aaec27c7dd54e61n/a RedLineStealer
2023-03-04n/aexe 9d01c6d5636c867639688a8f4742e259395b36ca2c75b9ffb5f67d4f37b0ae3cn/a RedLineStealer
2023-03-04n/aexe 4a6aafe66890ca65480aeb22dd2cd419a4925cfdd932bcfc4956ba0c6aebed0fn/a RedLineStealer
2023-03-04n/aexe d26cb8effa6bd46b4c70fbd4d7cb4db5d2757978e81c1130a0127521c052d6dan/a RedLineStealer
2023-03-04n/aexe e0648736c34376833175cee5a47adb885534e678c9f46c0a26fe42f6025ba49bn/a RedLineStealer
2023-03-04n/aexe fabf79492c909404c374abfa8a54b38ead7ec3b137c9c780e2ada58b52f2fb83n/a RedLineStealer
2023-03-04n/aexe be58a6811e443be08ed35bda4a1e7d69e869bbc0080743142e879c1bf683d3d1n/a RedLineStealer
2023-03-04n/aexe fb7e5f1d879ac4e8cae35e7916e18bb8de6ee084f25056c5496e572bf0df8f5cn/a RedLineStealer
2023-03-04n/aexe 3fc6e6301ccb372d88614b5e3dd94564fbe1afc829b39370a91b82226531199cn/a RedLineStealer
2023-03-03n/aexe b9d56f3a1f1f085d13d5adb150859d9de17fa53469364ddedc754b4af9eb02dfn/a RedLineStealer