URLhaus Database

You are currently viewing the URLhaus database entry for http://194.169.175.118/trafico.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2726601
URL: http://194.169.175.118/trafico.exe
URL Status:Offline
Host: 194.169.175.118
Date added:2023-10-30 07:03:06 UTC
Last online:2023-11-13 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-10-30 07:04:04 UTC to matrixllp{at}skiff[dot]com)
Takedown time:14 days, 11 hours, 5 minutes Bad (down since 2023-11-13 18:09:39 UTC)
Tags:dropped-by-SmokeLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-13n/aexe fb3946aa443e59af11ecef144d3dfc114e33560e8ba71b68f3079099c57fd653n/a RedLineStealer
2023-11-13n/aexe cfdfdd37c1567fa8e327b39f1d44c118ab970fd73b29207716fa363e452b8987n/a RedLineStealer
2023-11-12n/aexe b3054ec2cd444dd61b49dda8c06e50c7d699ed515845f9feb44abf24287f8899n/a RedLineStealer
2023-11-12n/aexe 2e882e269818b9a762ccb4935e001ed49cdebcbaae3c24446f211f2fd2777acan/a RedLineStealer
2023-11-12n/aexe 3b9da222717a1b6758164d5d8e30a8625045ce17422bd2042f4c2960fdbe4671n/a RedLineStealer
2023-11-12n/aexe 272ca6314de02c4201f131a35b534d99dbb0ff081231d28d1f3135a197ca5a3an/a RedLineStealer
2023-11-11n/aexe c43ba1b96be77608af07fa060f47f99604610ea712bf71f19c2d32f70b35beb1n/a RedLineStealer
2023-11-11n/aexe 89d8e236b302f2e54d73f2a4c5efc09d1ae346a6121c4f3e6b5ad14fe9d5e48dn/a RedLineStealer
2023-11-11n/aexe fed9fe7c0027acbfeb05ae652b70d981ed3aabb54559eb6bfb1ba24a27e1c3a7n/a RedLineStealer
2023-11-11n/aexe ecaa0c2607027b807cd7092124f7e3ce4982fb7a05436ede18e2fb3b66a48528Virustotal results 27.78% RedLineStealer
2023-11-10n/aexe b133c1e7941c9696fdbc435500980d2995ad20140f8e982f91c85b3db167dadbVirustotal results 50.00% RedLineStealer
2023-11-10n/aexe d5b7a79166881721645205a8333c1183a7cba0d7ca6695ebd3f6bac2955acb73n/a RedLineStealer
2023-11-10n/aexe c52971aae1908e552ba0df7e43d63a00c1ea5c7c3cd43476fe515adb1f00775dn/a RedLineStealer
2023-11-10n/aexe 2bdb0549d0d39ab13fe0091cc27a4c9a2ae5e94d47502cd6e7b8ee3edd9ea33bn/a RedLineStealer
2023-11-09n/aexe 5efdfa9a381962ab18fe88c5256b0b931fbcc4879b19ad20cf9f349d404ca49cVirustotal results 44.44% RedLineStealer
2023-11-07n/aexe 3c1981d8bee4d8b569627d96e0b027308748e318eead269028db9bde324c3908n/a RedLineStealer
2023-11-06n/aexe 0c1685ef988692591f6e1c4985d3a1f00ff1c41e8767b0fa967ba3478d08ab80n/aRedLineStealer
2023-11-05n/aexe 4af37cf61ea93d5b3aa752215263f88a0b3f9336b0850e5e84f70e0bf231674fn/a RedLineStealer
2023-11-04n/aexe ff46b5ca93104e2f213864f9ef0cbd1835a6a758f2f071362fc389c07c1042bdn/a RedLineStealer
2023-11-04n/aexe 000d0ede3217d82fa0951d17a5ac9debfe3dea991709ad0c098dece6df6a08f2n/a RedLineStealer
2023-11-02n/aexe e9955f64d2e3579dc9d2edf2b75a4c272738f3d78d05b16ebfa7632cc1d89651n/a RedLineStealer
2023-11-02n/aexe 7604cbc90d4ea6de7e2543babbfc4095cd0702bc268aba7523e62d676c8670c3Virustotal results 33.85% RedLineStealer
2023-11-01n/aexe 1746a6d6552b198a9fccf59e0b0d30ae7ce4848029e0f8cbdb27848e10ecb5e1Virustotal results 30.56% RedLineStealer
2023-10-31n/aexe 6f12232e159de661dadd56f6f17a36a0d4e6ae24eba5c06f54fd2f7a8763feb0n/aRedLineStealer
2023-10-30n/aexe 880265cb3889dd109ac84a6756367ae56b73b483343a84a42fb35d16c816ec71n/aRedLineStealer
2023-10-30n/aexe 7ffa3cf71ff6e8aec4029586dcca55a61edcd799212eb14b7a18073fea4e8c5dn/aRedLineStealer
2023-10-30n/aexe 72674e9a3c32d5457c98ef723b938abc0295329c7ec58f9e07a0cb1e99631f48Virustotal results 71.01%RedLineStealer