URLhaus Database

You are currently viewing the URLhaus database entry for http://176.111.174.140/zbi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3076564
URL: http://176.111.174.140/zbi.exe
URL Status:Offline
Host: 176.111.174.140
Date added:2024-07-29 05:31:13 UTC
Last online:2024-09-14 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-07-29 05:32:14 UTC to abuse{at}changway[dot]hk)
Takedown time:1 month, 17 days, 16 hours, 24 minutes Bad (down since 2024-09-14 21:56:51 UTC)
Tags:64 BlackMatter exe lockbit LucaStealer RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-28n/aexe a38e3e82e522f7ecedfc51da3b44b9013bde09383f565a79a31b36e2e313c60cVirustotal results 72.00% RedLineStealer
2024-08-16n/aexe 315d043b99f988ce9d9f69d7225292eb44623a97c1a029933b62ede699fa9f13Virustotal results 85.14%Ransomware.LockBit
2024-08-11n/aexe cd1837ab88989f53ec170c57f403d3712e4770494c2dac3a586e9d7503dcac48Virustotal results 89.19% Ransomware.BlackMatter
2024-07-29n/aexe 191272e200345dcb0a7a8c8c975a8b07847f07b9d9f0c3af472fdb88092aee0bVirustotal results 32.00%LucaStealer