URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.68.144:8000/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2689036
URL: http://77.91.68.144:8000/1.exe
URL Status:Offline
Host: 77.91.68.144
Date added:2023-07-24 15:25:11 UTC
Last online:2023-09-26 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-24 15:26:06 UTC to hostvpsvds{at}proton[dot]me)
Takedown time:2 months, 3 days, 21 hours, 30 minutes Bad (down since 2023-09-26 12:56:47 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-25n/aexe 082dacaa2975e41d75cf4a03a83cd2832054f9ae2f212192b4b8c26ca434a17cn/a RedLineStealer
2023-09-11n/aexe 6230bbc1806416197b90876500a4a9e684ebd79ffbe33e6c9097776bb662f07aVirustotal results 27.54%RedLineStealer
2023-09-05n/aexe c1a87fdc0482eb361024523830727c737f773480a6c70f5273a43a3130551073Virustotal results 25.35% RedLineStealer
2023-08-30n/aexe 333bdff356c026200910212a646d7fcdb335b9fd9c6a58e2727e8b5d1b205538Virustotal results 29.58% RedLineStealer
2023-08-22n/aexe 60c27c6ec35be6f09fc9cbacc21780355c3dba31a297689361ccc3b3ea557e1cVirustotal results 44.12% RedLineStealer
2023-08-15n/aexe f3831b9ae0666059a0eff73f1e9f836afd662f6ce309deaf2f73e7e849e8a2ecn/a RedLineStealer
2023-08-07n/aexe 5f6f9a31930abd39e0c7e659633ae09645254d8714d32266c491e6a2424a1d48n/a RedLineStealer
2023-07-31n/aexe 1e788187fc11848b9859e3edf7270a692e2ef34f9f2dc1653c25e6da6fbbf937Virustotal results 25.35% RedLineStealer
2023-07-24n/aexe 0279688cc1957dc9ebc67463be23871fae9efb158042e8fce79f4cc0e4085785n/aRedLineStealer