URLhaus Database

You are currently viewing the URLhaus database entry for https://upload-wefiles.com/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2615741
URL: https://upload-wefiles.com/svchost.exe
URL Status:Offline
Host: upload-wefiles.com
Date added:2023-04-22 01:53:05 UTC
Last online:2023-06-05 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-03 14:22:07 UTC to abuse{at}alexhost[dot]com)
Takedown time:2 months, 23 days, 17 hours, 10 minutes Bad (down since 2023-07-14 19:04:51 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-29n/aexe c3605d9a7e5cd2f57b09f4e5721b9817df3803e113d10cf8a70859cb73d02e3dn/aRedLineStealer
2023-06-23n/aexe 9802c511f650d5eb611d309889655ac2f8daab5f87c30463b2505da99076192bn/a RedLineStealer
2023-06-20n/aexe fd9b0bcab91a3899bd4720e00819f2c2e0cd5d5cc084e18e9f86b489e2b995a9n/a RedLineStealer
2023-06-17n/aexe 0f842fbfcad83b99c49c7c8d21c4682e23808d6b44dba3847382a54bc8a9d2f4Virustotal results 50.70% 
2023-06-14n/aexe 708f8645d7490a37f453e560f3b451d4cd2383882f3b328ecc0c030fec12aa28n/a 
2023-06-12n/aexe 34cd4efd5b358e557b88e0cc4a3bb16019664d074ee0c9b895ad49c44b2ce2dan/aRedLineStealer
2023-06-10n/aexe e1658d982758514877f382b0c5cfda1ce99720bd7aa707f36325981fe0a5a964n/a 
2023-06-08n/aexe ee214b4a769770425ce6a30af6abf3330b708c5e2da8694c482a403e4aa43d30n/a 
2023-06-06n/aexe d1500c9d1f282e94f693ad2fc84ff732551c2b7020c86c03dc22ada142b91460Virustotal results 45.07% 
2023-06-03n/aexe 117923fa4c78bd37c924ad1e59c636a9a9337d4d58df9e1779be1c0e3a94151an/a RedLineStealer
2023-05-29n/aexe aa1e3e22f8f01590aab1cefdcac89785b76f4e0aa33958af5bac5c5a889ef884n/a RedLineStealer
2023-05-28n/aexe 111e8214fea23543ee499ed1a5d77da8a2a0002359c45d011367b3313bd3d906n/a RedLineStealer
2023-05-21n/aexe bbd22134bbbb870710356d411613f6b249f9f38a51841e9780eb2a11340f6728n/aRedLineStealer
2023-05-15n/aexe 8925cfc866e5b52ad7055246b75d70d5ddba6dcac8ea6daf4f34b9a532a6e806Virustotal results 33.80% 
2023-05-09n/aexe aa0f96be29bd7888fdbd195fb56e741aad5f13b9a1df4a7e74a085924240f597n/aRedLineStealer
2023-05-08n/aexe 929e8a2598a4046d4064b608af291b658872c5f2a6bc089467bdf1925fce5aa6n/aRedLineStealer
2023-05-03n/aexe d5b3cff7109056f5f8c9b8944556caf49ae5071a6f93a6fb7a6c4916fca2a52fn/a 
2023-05-02n/aexe 0f40352a01ff3d7ce8c791bfce5029c4765ebdc4802210e605392d7a49d4d94en/a 
2023-04-24n/aexe 394a86f45a0061e79dd2923a7db4256082edd7d6a278edd4ef7ed88c9b39acc8n/aRedLineStealer
2023-04-22n/aexe 6d45f102f456a95eaf31e9a1851c031e6fccbc852c8d56e1fc665aea7945579aVirustotal results 34.78%