URLhaus Database

You are currently viewing the URLhaus database entry for http://47.104.173.216:8081/GGWS_UPLOAD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2863561
URL: http://47.104.173.216:8081/GGWS_UPLOAD.exe
URL Status:Offline
Host: 47.104.173.216
Date added:2024-05-25 15:22:09 UTC
Last online:2024-06-02 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-05-25 15:23:06 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:8 days, 6 hours, 4 minutes Bad (down since 2024-06-02 21:27:17 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-29n/aexe f82b4dcf4c2cc5b49ef6bcf281762f00705553ee0a3e122f3a5b0f3c2ceaae2bVirustotal results 37.84% RedLineStealer
2024-05-26n/aexe 102873ced15d70c2e8271f72d06c28d169a9d997768aa87a9de8bcc16419183bn/a RedLineStealer
2024-05-25n/aexe 44c5191f1061cc9340498b5841ac6b3e2488ca5b5e5e8a812687bbf864125a61Virustotal results 35.14%RedLineStealer