URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.97.131/333/ed1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715463
URL: http://77.91.97.131/333/ed1.exe
URL Status:Offline
Host: 77.91.97.131
Date added:2023-10-01 13:36:06 UTC
Last online:2023-11-07 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-10-01 13:37:05 UTC to abuse{at}sap-dedic[dot]ru)
Takedown time:1 month, 7 days, 8 hours, 48 minutes Bad (down since 2023-11-07 22:25:55 UTC)
Tags:77-91-97-131 bookinggoogledrive LummaStealer RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-11n/aexe f8412c9a8d210409888fb0aed2120d12b4be1cb480cf24ed66b13ccbfef6d928n/aLummaStealer
2023-10-01n/aexe cef823e614c07e8813c9e32db81d8dc6a20d00a3e55aca97a6a5c340aa6e5d1cVirustotal results 41.67%RedLineStealer
2023-10-01n/aexe 61d1514fb945224e3134e0a28f6fa194938148723486cc30c9f1e029008303cdVirustotal results 58.33%RedLineStealer