URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.97/download/WWW14_64.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728742
URL: http://194.49.94.97/download/WWW14_64.exe
URL Status:Offline
Host: 194.49.94.97
Date added:2023-11-07 08:10:26 UTC
Last online:2023-11-24 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-11-07 08:11:08 UTC to madhost{at}tutanota[dot]com)
Takedown time:17 days, 7 hours, 45 minutes Bad (down since 2023-11-24 15:56:57 UTC)
Tags:PrivateLoader RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-24n/aexe 172c25ce4a5916f38026250b5799b318751216eb858a6b1230b039527115af52n/aSmoke Loader
2023-11-24n/aexe 739219ab2729b639d38c00e92f9e80aebc3073a353a0ed135fe65d5fa5130261n/a 
2023-11-12n/aexe 76961b32dfaa92f07b0cdf92f0b45c7e3c9acde075aeb30197e56bd3cce4c6afn/a PrivateLoader
2023-11-07n/aexe 1f0a1a7674ad868c99421fc13b0457de7ab612ca5948ae7cd045db355720e1fdVirustotal results 66.67% RedLineStealer