URLhaus Database

You are currently viewing the URLhaus database entry for http://94.142.138.20/version_s/upd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711877
URL: http://94.142.138.20/version_s/upd.exe
URL Status:Offline
Host: 94.142.138.20
Date added:2023-09-15 10:29:07 UTC
Last online:2023-11-10 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-09-15 10:30:10 UTC to support{at}zerohost[dot]network)
Takedown time:1 month, 26 days, 2 hours, 57 minutes Bad (down since 2023-11-10 13:27:55 UTC)
Tags:exe LummaStealer RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-20n/aexe 788b5f04728a23442dfa17512a2fdafb5bc18d514541b2180fe19c512fa2d69en/a RedLineStealer
2023-10-20n/aexe 23efed277ee2a1a262d242916556f28eeb5a4629a181ba6ea434f8d8dfaf68f2n/a RedLineStealer
2023-10-18n/aexe b3e08dde8c5ed9933ca24878f75a15d727751297f3854acd2400b52300841646Virustotal results 48.61% RedLineStealer
2023-10-08n/aexe dac0157dc23f42f559321b4f5b578ef9a7e938032838616b5ce9fffd2efa95can/a 
2023-10-04n/aexe 2a551466afe3b8ee2c53c1c55edee43ed789ce59c296b90a9db6682b16971758Virustotal results 16.67% Spambot.Kelihos
2023-09-22n/aexe 88e58a37f63f4c0eb1f7fc9d1dab9dd5bdca253bf1c2de57b1ece47b83b6197dn/a Spambot.Kelihos
2023-09-19n/aexe 7d6850f738a50e92223d4cbba127cbf0fca61b328304cd38a255877b87ad8565Virustotal results 35.21% RedLineStealer
2023-09-18n/aexe b7ede55a3be0d0518e53121c10ef901415bdb7360441772c11f024d3b81bd305Virustotal results 39.44% RedLineStealer
2023-09-18n/aexe d6519a35b0bf505839cd9fa2a638c0636b531e5ec2abaecf665775776b86cb78n/a RedLineStealer
2023-09-17n/aexe e0540c2e77506c5a91a9d043b8f561f9aecdd5cb0c772b1d3edd442a65bcedd1n/a RedLineStealer
2023-09-16n/aexe 4d689288fda075e937a5bc00afd4b2fb077d5aef8ac767fb415f8b7df31fadd6n/aRedLineStealer
2023-09-15n/aexe a3ecec0dc331e402e4c9ae68e1c5554b373e39298800e1a74da6a320aafa940eVirustotal results 28.17%RedLineStealer
2023-09-15n/aexe 845b3e0ef3bf0235321063d4ffbd013212abcaa9b4104eae1706902214c38e00Virustotal results 27.27%LummaStealer