URLhaus Database

You are currently viewing the URLhaus database entry for http://47.104.173.216:8081/STHealthClient.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2863581
URL: http://47.104.173.216:8081/STHealthClient.exe
URL Status:Offline
Host: 47.104.173.216
Date added:2024-05-25 16:11:13 UTC
Last online:2024-06-02 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-05-25 16:12:06 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:8 days, 0 hours, 55 minutes Bad (down since 2024-06-02 17:07:43 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-29n/aexe 61ea68229965be4facdaaacada953ad6139b6f4107a4e2d1631ca4cd9ece528aVirustotal results 33.78% RedLineStealer
2024-05-27n/aexe d550397a71e1fc77be3460d1742f1df63d43ba74487a10ec96befc1c768768bcVirustotal results 28.38%RedLineStealer
2024-05-27n/aexe 04d021504e1cf5356ed757fbfa2b9e733851deb7fc96ae3fcdcfe656ba763351Virustotal results 32.43% RedLineStealer
2024-05-27n/aexe fc9f3da8559a7aad625dec7975ab0790c2c0c7503e32d570721550fa3957662fn/a RedLineStealer
2024-05-25n/aexe 0d201c707970f939a33dadfd8ae86aa6070db1f63dbed7c386b449f8fd06f0ceVirustotal results 29.73%RedLineStealer