URLhaus Database

You are currently viewing the URLhaus database entry for http://89.185.85.189/balalaika.php?filename=Shuelx64.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2705838
URL: http://89.185.85.189/balalaika.php?filename=Shuelx64.exe
URL Status:Offline
Host: 89.185.85.189
Date added:2023-08-21 07:10:15 UTC
Last online:2023-08-21 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-08-21 07:11:15 UTC to abuse{at}aeza[dot]net)
Takedown time:7 hours, 19 minutes Good (down since 2023-08-21 14:30:39 UTC)
Tags:dropped-by-PrivateLoader RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-21Shuelx64.exeexe 96dd07bd64cbe4630378e1fedf380db4acce8e0fad4a3f650126fda5e4b8fe2cn/aRedLineStealer
2023-08-21Shuelx64.exeexe 8ff1f9ef3ebff16b143cee998dceec3fb9b016c3dc4f21730f1d8edc0bd904bdn/a RedLineStealer
2023-08-21Shuelx64.exeexe 70e2270567834e6be702a150f2a32112f4a6797499e1f4bce2b20bc8e80bb22bVirustotal results 41.43% RedLineStealer
2023-08-21Shuelx64.exeexe 680b9f5fe758d33fe29491c3b071d5b0cce2bc8d941382a58670b632a8f51eban/aRedLineStealer
2023-08-21Shuelx64.exeexe 584252a4b7380835647fd110a74094d8991cb7afdfe0d1db2bb6034edb184c20Virustotal results 42.42% RedLineStealer
2023-08-21Shuelx64.exeexe 59835a3f4ca0edc1491196024e33c0e0c0a0d399527a9d00f3cb9aec4f1e6a6an/aRedLineStealer
2023-08-21Shuelx64.exeexe 8fa01247b623630a85d321f3c0a883d2a9d42feb5a0be42f2055487c0095fbfbn/aRedLineStealer
2023-08-21Shuelx64.exeexe 577e25a072c7f933832e4d9b73bd806bf77fa56207f3c12384d4bebd03de3d7dn/aRedLineStealer
2023-08-21Shuelx64.exeexe 736ce6b7e36b2bf8e9fa7c438b5382635b400fd38dda3e775d3514699491c5a9n/aRedLineStealer