URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.75/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2762638
URL: http://91.92.240.75/1.exe
URL Status:Offline
Host: 91.92.240.75
Date added:2024-02-16 18:21:12 UTC
Last online:2024-02-17 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-02-16 18:22:06 UTC to abuse{at}limenet[dot]io)
Takedown time:16 hours, 11 minutes Good (down since 2024-02-17 10:33:51 UTC)
Tags:dropped-by-PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-17n/aexe f8c472c817f6c8a4dfffd64f338ae1c8c2c118e463f07558f2f7dd9838cc1fa2n/aRedLineStealer
2024-02-17n/aexe 3d057b69010556e0ba1de55ec617e3797f41909165533ed00f4bc098f20360a3n/a RedLineStealer
2024-02-17n/aexe 1fe7088b62bb734fbcf44343adb2f33a28acbb7d31103c65b02fc9af3fd4493dn/aRedLineStealer
2024-02-16n/aexe 5240773ffa3a72a2d31a6a4aced652979b2662efaab2c7bcc28a1a67bd5b7696Virustotal results 37.50%RedLineStealer
2024-02-16n/aexe 99db76619552e10826a620b4305a50915a10789522ff3668be2e611ab74a951fVirustotal results 40.28%RedLineStealer
2024-02-16n/aexe 6b3442f3867aad390ecbe493e952df11f40ae02727d068b4fcc2485513706257n/aRedLineStealer