URLhaus Database

You are currently viewing the URLhaus database entry for http://weatherwindows.pk/7zip.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:942364
URL: http://weatherwindows.pk/7zip.exe
URL Status:Offline
Host: weatherwindows.pk
Date added:2020-12-26 07:44:09 UTC
Last online:2021-01-10 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-26 07:46:03 UTC to info{at}invs[dot]ru)
Takedown time:15 days, 1 hours, 23 minutes Bad (down since 2021-01-10 09:09:31 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-06n/aexe 9e05286ed6cdc997059456e67bb70bdbc8d64e6355302faf854e5826569f1576n/aRedLineStealer
2021-01-06n/aexe d72ff6b06bfc6f501552b096fac29e16ad2bbb194d6b462485a6a07869aedd98n/a
2021-01-05n/aexe e13c6db4ac0862583bb07b2459b7badfa97d4f6d079672bdf12122adab7fca3dn/aRedLineStealer
2021-01-03n/aexe 392f8d77a3758e96ccc1193d603d88f312b572e99d5baa63e3e9fab307373518n/a
2021-01-03n/aexe 5ff2dbc84ab8b4e784a404ef9457fb12b7e05ed5808e344f7453c9028075388dn/a
2021-01-02n/aexe 21a8b4f3ab485cfe8706c3f227548a950c1582550125dcb603f76d0623b0ab65n/aRedLineStealer
2020-12-28n/aexe 931210400364c50e45ab51294521789d451406a9538a38fd99cce928c9188f53n/aRedLineStealer
2020-12-28n/aexe 17f0a7a2d1f4d1167a0715e02b445a3895021694c187a96536c6eff58473d906n/a
2020-12-26n/aexe 771abcaf7448313442e2b56a227ca3273f97872133894cad5039e50b1f4426e8n/aRedLineStealer
2020-12-26n/aexe 3f793640a3756904d085de9d935d084026a34f458fcdb5fe2c8901d835069a88n/a
2020-12-26n/aexe 5caf05d632263d6fcb361a630f017850caebd0c9851888a755c0dae99062df7eVirustotal results 36.62%RedLineStealer