URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.72/3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728094
URL: http://194.49.94.72/3.exe
URL Status:Offline
Host: 194.49.94.72
Date added:2023-11-06 09:13:05 UTC
Last online:2023-11-24 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-06 09:14:07 UTC to madhost{at}tutanota[dot]com)
Takedown time:18 days, 6 hours, 48 minutes Bad (down since 2023-11-24 16:02:30 UTC)
Tags:dropped-by-PrivateLoader RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-24n/aexe 8dfae05eff92ce87acd6c78f6d1ae08f9ae5d1537ac6cbd4ba11c5ed457256dan/aRedLineStealer
2023-11-24n/aexe 7d969fd0a02104e41e9e377433bde1344c5d919b352184d7de814fe787c95702n/aRedLineStealer
2023-11-20n/aexe 141e1080063391b7da029f94989bfce5b81f85cbd89ab751c9755d23ee0cf80en/a RedLineStealer
2023-11-15n/aexe d61f6627d89d73a60f0098df9a2e44b47e30db28c24ce98712ca6baacd7623a3n/a RedLineStealer
2023-11-14n/aexe ce280a5928ef9078fbd8b0908cd3e48cf0f482bece56501e98bea57928a7dda3n/a RedLineStealer
2023-11-13n/aexe 960b4d86b671415cd404b6b144998bfba0576346fe90df2c7540ba42d879ce47n/a 
2023-11-13n/aexe c658712d3aed2fec2281d04a2d9650c72af23eee2c4258762efeef5c232c9230n/a RedLineStealer
2023-11-12n/aexe cbc0c2f6362096bbbc94ad223922b3c9749e41d0f52697e145ae0b9227ef4c05Virustotal results 8.96% RedLineStealer
2023-11-11n/aexe ede084e2e36e654562baede44cf8edfcc432d59f5a7178503f6a19043ce611acn/a RedLineStealer
2023-11-10n/aexe ec2d925069bf9b32f6c220216badb3ba6be315b6b589c4f3927a486959763566n/a RedLineStealer
2023-11-10n/aexe 7faf5362a86ec6eed395e596b3fed24fc935efa54fc9be0e1e121fc6cea3e8d0n/a RedLineStealer
2023-11-10n/aexe 48d3df2052df2755a7baee09af80f11986a31152c4575308ac8aae7f05b050ffn/a RedLineStealer
2023-11-06n/aexe 0f6464732f9c7428188f1f53dcee84f1eeb7821df69abfa866ea7ba7f06e0d56Virustotal results 44.44%RedLineStealer