URLhaus Database

You are currently viewing the URLhaus database entry for http://194.116.215.195/12dsvc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3189155
URL: http://194.116.215.195/12dsvc.exe
URL Status:Offline
Host: 194.116.215.195
Date added:2024-09-24 11:12:05 UTC
Last online:2024-10-03 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2024-09-24 11:13:06 UTC to abuse{at}cloudbackbone[dot]net)
Takedown time:9 days, 11 hours, 7 minutes Bad (down since 2024-10-03 22:20:55 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-02n/aexe 54cbc05805ba8d90a35ee888c4676f3abb19375be756ebe841a5db5908e9f80dn/a 
2024-10-01n/aexe c94f21254373c228e200a85422f611768978e785385d2802883cb1b75a0b31b0n/a
2024-09-30n/aexe cd85e3ca4693263c5bcda5e1dbc7d9abfb8def02891cb1ec37809d122b55b5b6n/a 
2024-09-27n/aexe 799d10acbb0e2886c4d32c771964f4c2cb47f93c817cdc26a9acaefa3ba042cbVirustotal results 58.90%RedLineStealer
2024-09-25n/aexe 7d6e4e01c452dd502361640ee095e2bee35e3f55fd11edc9e94c3580d2c132b5n/aRedLineStealer
2024-09-24n/aexe c0f8b5afad6fab4136affd308519c36e3779d597413d00e79e7f939bd7bae782Virustotal results 65.28%RedLineStealer