URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/revada/66e01056bf2b0_crymeta.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3174206
URL: http://147.45.44.104/revada/66e01056bf2b0_crymeta.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-09-15 12:56:35 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-09-15 12:57:08 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:1 month, 7 days, 3 hours, 33 minutes Bad (down since 2024-10-22 16:30:40 UTC)
Tags:RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-13n/aexe 1d3c0a481143e11abdb1207f711c579bc164054e233fc19bd8598853e7849b25n/a RedLineStealer
2024-10-05n/aexe d725c9514ddde4ffe5972367b323edbfdd1429e128b22543d6c15dbf29c44eb9n/a RedLineStealer
2024-10-04n/aexe 5dbf910dab53cd8527d04f4af04fec8554e86a9596a48155a6cdf710f9772c3dn/a RedLineStealer
2024-09-29n/aexe 7f4dd8ef4becee8024aab9c863a5ab9d6a70ad57e21a80b712eeef090396ccdan/a RedLineStealer
2024-09-28n/aexe 1a9f354cfab983f1c0602ebc61becf6f97f58e8a6f729a13f8ce1b42f70fe98fn/a 
2024-09-28n/aexe 4ea38359b2ae56ef32a14baa734a060e64734c5c79e77266ebd78b46f5d79dd0n/a RedLineStealer
2024-09-20n/aexe af579d7ce27a2217bae1dfb66edf87e77aaad64c0f5eeb6483b8d3035cde3ca1n/a RedLineStealer
2024-09-15n/aexe 3ec49e14a495f9bdafb8944db9125c0e8f7f4258c285962df393c8918b0665ddVirustotal results 68.49%RedLineStealer