URLhaus Database

You are currently viewing the URLhaus database entry for http://217.8.117.132/qefyur/6q7jcqdx/belial/files/drop3.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:370368
URL: http://217.8.117.132/qefyur/6q7jcqdx/belial/files/drop3.zip
URL Status:Offline
Host: 217.8.117.132
Date added:2020-05-28 07:16:03 UTC
Last online:2020-06-13 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-05-28 07:18:02 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:16 days, 9 hours, 56 minutes Bad (down since 2020-06-13 17:14:44 UTC)
Tags:opendir RedLineStealer link zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-02n/azip 899c0d30fcb2af68e6d0e4f14b0441938b32ae229d08cd0267f26222ee86cf40n/a 
2020-06-02n/azip b0d858285269245f6c0b81b253da7d16d9f192ead0e9db9e9a2ad4e8f3dde0acn/a 
2020-06-02n/azip b27305ebe415073b5203a89b8aa2066fc90763f3e3f0a88e1f723edb00ce3e58Virustotal results 12.12% 
2020-06-01n/azip 74fe01c829821ca7f42f385a5ef57e242c058dccb36ad60564f9912a51e0ab82n/a 
2020-05-29n/azip fd40240f7874f6324e0ecb17a3f1f7e095d3feb079b56da3694dac833bdc6a0cn/a
2020-05-28n/azip 41d357be2001d13ea18b5e64e662d7a59b7034e2f3a08b0388bff411695ef9f5n/a 
2020-05-28n/azip 7036561a038efa5fbb53b451c5114a06ef491072b895592cdbc856bb258cb968Virustotal results 21.21%