URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.68.144:8000/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676435
URL: http://77.91.68.144:8000/2.exe
URL Status:Offline
Host: 77.91.68.144
Date added:2023-07-04 11:51:04 UTC
Last online:2023-09-26 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-07-04 11:52:07 UTC to hostvpsvds{at}proton[dot]me)
Takedown time:2 months, 24 days, 0 hours, 41 minutes Bad (down since 2023-09-26 12:33:42 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-25n/aexe e1b4cadadbfd237aad0fd18d39f0abbcb33366a5622fd46f8f7cd4c0285d9afen/a RedLineStealer
2023-09-12n/aexe 54d31e0461470d4eb8173ef72904c04ba6a85b811a7b44b77a31fcb02db054e0Virustotal results 33.33% RedLineStealer
2023-09-06n/aexe ec53492ebc0d4d53bf2fc48b2dc7c80092c85eb1c6da228e99a3b89653d16edbn/a RedLineStealer
2023-08-30n/aexe e00a85dcb7d1d9aef4ff4ec0d7f1c94cd48fa78455bf691f448870f75dd2b921n/a RedLineStealer
2023-08-22n/aexe a7abd4eecc856849796e75a2b1c7f10ce3116b411430f64b0720a2a2ca081d17n/a RedLineStealer
2023-08-01n/aexe 0a54ad87c4e39a5e3cd04fea27eb604b7aa7a4461c0d285f7e9ea28c9ae89d1cn/a RedLineStealer
2023-07-04n/aexe a1de034354cb572f503d34ab3823b9c2a70607b10f6a380aa2002e1d81074729Virustotal results 36.62%RedLineStealer