URLhaus Database

You are currently viewing the URLhaus database entry for http://hellousa.info/filestoload/cli/remeus.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:896394
URL: http://hellousa.info/filestoload/cli/remeus.exe
URL Status:Offline
Host: hellousa.info
Date added:2020-12-07 13:37:07 UTC
Last online:2020-12-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-07 13:38:19 UTC to abuse{at}selectel[dot]ru)
Takedown time:8 days, 2 hours, 18 minutes Bad (down since 2020-12-15 15:56:20 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-14n/aexe 2b14c418ece19eda5bffd6234b71eb9b60eb9f07c80a3850fb7371fed92ad63fn/aRedLineStealer
2020-12-14n/aexe 16e2f02323bffb1363b00f294c442412db60fa44d63b06cb0098949912d9c3e6n/aRedLineStealer
2020-12-14n/aexe 5637daf1b0a5e312bf2118b89083c186fa32f074a12006ef7df0e49ce51f40c1Virustotal results 12.86%RedLineStealer
2020-12-14n/aexe 0c087b76fe070b51aa2d0bf468c6dba75c3e91d318eac19f33966283a37db916n/a 
2020-12-13n/aexe 06e874e4445834d151626e6c58ecd69d10373ba4c8b5b566dd10129acdb11065n/a
2020-12-13n/aexe 3eeb8c98b2d09b360ec99669d6d7053e68e2c764321860b9be44b50a7a19b7dan/aRedLineStealer
2020-12-13n/aexe ab84aed43b30ced6e514cd2a1191307294bd4f3211813c5de99aa0ebbfedd215n/aRedLineStealer
2020-12-12n/aexe 4ca9181b184aa8af619c55d2ef0e00246ad900162422990502ebf7be4975d19fn/aRedLineStealer
2020-12-08n/aexe 45c3f3af9f9d0c905dcb43df313ecf62364fa7cbab78236a3c049700556b1d63n/aRedLineStealer
2020-12-08n/aexe f1f02609df5674a0ad67ce6d2bd2f07dd7616eb2995b07f31ae431a956036ae9n/aRedLineStealer
2020-12-08n/aexe ba483bee9e68e055952e71255eb24bd6ca52c1238d3efe96bcb66506e80e6792n/aRedLineStealer
2020-12-07n/aexe 23fd2f9a3457f89375c711dade5bf4ca1afe47df345d0eef6c2d48fdc09064bcVirustotal results 19.72% RedLineStealer
2020-12-07n/aexe 8e260eb76e2774843e8e79bfb5adef7a9eb06efb28161c9101a10accb475a54aVirustotal results 27.14%RedLineStealer