URLhaus Database

You are currently viewing the URLhaus database entry for http://103.170.118.35/tungbot.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2630931
URL: http://103.170.118.35/tungbot.exe
URL Status:Offline
Host: 103.170.118.35
Date added:2023-05-13 01:33:06 UTC
Last online:2024-01-19 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-05-13 01:34:05 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:8 months, 11 days, 13 hours, 43 minutes Bad (down since 2024-01-19 15:17:25 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-25n/aexe 52de83987941b92875cecdd1661cc2757eae4f02ef564fd2e147d06eb9d8ab44n/a 
2023-07-22n/aexe bc929754d1fee83d4faa1cefb6bc48e8304ff125606972962daa0799973df8b8n/a RedLineStealer
2023-05-27n/aexe 3d5d91613033f94c7b22b38b15351089265d158fd2fb6dabc9d671592c2aabb8Virustotal results 71.83%RedLineStealer
2023-05-13n/aexe 23486011905dbe13c3dcfb1766083e604090cefdcd7620bccb7f3bb4c9380b1cVirustotal results 81.43%RedLineStealer