URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.72/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2729438
URL: http://194.49.94.72/1.exe
URL Status:Offline
Host: 194.49.94.72
Date added:2023-11-09 21:34:06 UTC
Last online:2023-12-01 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-09 21:35:06 UTC to madhost{at}tutanota[dot]com)
Takedown time:21 days, 9 hours, 57 minutes Bad (down since 2023-12-01 07:32:46 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-24n/aexe 0d54dba0063957d8632b5107a0660190dacbbd23c543510dea5ec78177ff0c09Virustotal results 29.17% RedLineStealer
2023-11-24n/aexe 1c892b221cd61d2fa086bfabb54b81a551af660a0b6aa0894362951e46cfa87cn/a RedLineStealer
2023-11-20n/aexe 8f1ecf2e9cf29f96f0de9188e38247116c172b851bffcaf1e19b489d6bb160e4Virustotal results 5.56% RedLineStealer
2023-11-15n/aexe 7acf0eba2165fcdfc72338959e9add02c362918c8451a0313c4ef797ae337abdn/a RedLineStealer
2023-11-15n/aexe 3670c843eff2bcc2566ecdb2d4e30e0b13b8cde935933c00385503b26b3abd33n/a RedLineStealer
2023-11-14n/aexe 8c239b7ab61ba158fd64e4ee080b23d024d27f63b1ce055f69f8fee6c1b67b1dn/a RedLineStealer
2023-11-13n/aexe 564ad08d79345be7121e76d778719928ddb37af7208368ca6dfcb703bc7168f4Virustotal results 8.33%RedLineStealer
2023-11-12n/aexe e0f318560fad28284276f0827816f0c69fbbeb8691069f74520ca89caa0285cfVirustotal results 8.96% RedLineStealer
2023-11-11n/aexe 12bd2b7714f488b77704aeb676e56bc6cbbedba4738b4a45f27c6ef38cfda771Virustotal results 31.94% RedLineStealer
2023-11-10n/aexe 733e2c2b9b6f626b4395f5b12a9920b5f6d0e59fb9b61e28c85c7476da942436n/a RedLineStealer
2023-11-10n/aexe 57ff370cffa136c8e6cb1f0731c9b41406d550b49461af095639d8d84cfdbdaen/aRedLineStealer
2023-11-09n/aexe dab0e67f3eff66cbdc1b3d12e26b50a5e76c736935f755dfbea422b6e3976f88Virustotal results 55.56%RedLineStealer