URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.64/files/TWO.file which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2819457
URL: http://5.42.65.64/files/TWO.file
URL Status:Offline
Host: 5.42.65.64
Date added:2024-04-20 10:53:06 UTC
Last online:2024-06-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Xev
Abuse complaint sent (?): Yes (2024-04-20 10:54:07 UTC to abuse{at}lethost[dot]co)
Takedown time:2 months, 8 days, 5 hours, 8 minutes Bad (down since 2024-06-27 16:02:23 UTC)
Tags:CoinMiner LummaStealer phorpiex link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-17n/aexe 63ce5a5c895df81cf05bd0d93f568f5d0f0008bb02c47fa0ce19af76c724cc1dVirustotal results 50.00%CoinMiner
2024-05-15n/aexe 3236a013ff341fb520f35a94d3f702f5ca24f5f2b6f679933bd73942238ac147n/a Phorpiex
2024-05-14n/aexe 5a387e107c83b39a54fa7718c2d4452e2360f1d96d84f99fbf52bc59a21e26a4n/a CoinMiner
2024-05-08n/aexe 0bd29634c1139a443091cbabe87c16b4f26d8bb8518d5c439baf740b2d7e0954n/a 
2024-05-07n/aexe c7752b6eab44f4b1c456648b80a4a6139ea2654cbc1915b1bd7cd9f09e974565n/a 
2024-05-04n/aexe a98cb4156fd445803d7d0f6cb25043e76a93a9f546a1b8b767998c82f6bca462n/a LummaStealer
2024-05-02n/aexe e953ddb924a32ab5a78488d75e8f753832293eece41b98eb7227651dfe7ed8cfn/aRedLineStealer
2024-04-28n/aexe 789e0b9f3e56d4ace92a1d7142a8cb82d39fbfa74d34f829dd47479e85ababc1n/a 
2024-04-20n/aexe d55e86610dcad29c3d2857d9dae91aa51228b1fa001ea2d7bda88b9a2b5570a9Virustotal results 40.00%