URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.77/ds1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:948786
URL: http://185.215.113.77/ds1.exe
URL Status:Offline
Host: 185.215.113.77
Date added:2021-01-04 13:24:06 UTC
Last online:2021-08-16 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-04 13:26:02 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:7 months, 13 days, 22 hours, 18 minutes Bad (down since 2021-08-16 11:44:11 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-05n/aexe fa98235aae1687afb628d39a16645b6d2f4afeb97d113229c660425464e296c2n/aRedLineStealer
2021-07-23n/aexe 40cd463ec941b66e1f65ea9e1e9ca7ab0c0211ebc38ea7250eaa3a9012c61cf9n/aRedLineStealer
2021-07-15n/aexe 3e3a37958735147c13c9a9104d248cd1cbdd21a748acde9307aad55d8b25c704n/aRedLineStealer
2021-07-13n/aexe a24f0475956974b982907daec525ac871a797740c18d691e81b697b7ba05c1e2n/a
2021-07-08n/aexe b515f2b1b2da802508e2d152393df5216154d2a18b1a7d16eabfc967bd0e9222n/aRedLineStealer
2021-06-30n/aexe f0384e2d435f1956072c37acd61add6ad74eb9249e282e8a5fccce4bcdb13d90n/aRedLineStealer
2021-06-04n/aexe f17eae9c3df34f0216c77ca36485b54fd7b4574eb318fb0144e8c3ab73a0d336n/aRedLineStealer
2021-04-30n/aexe 6cbfb1c60567bc22a202ba90c7a6cd377a133ae17b34dc5bef7d4e4808a66b8bn/a
2021-03-30n/aexe 6dda75f44dbe8642fa6aa581fba2bbf65e02fb4deef38d5b0563d75fd486c3f1n/a 
2021-02-16n/aexe a44811258fb1eb694a7c2b561b2c993df6492960be2ce4d749bfe5a172626e27Virustotal results 24.29%
2021-02-08n/aexe 0e4faaad6a44f55e0e23118c169e33ae95b2e8b2950207b939e561497f00d0f1n/a
2021-01-24n/aexe 7e7720c687925a6647d2821e0dd041b8f302d7fa31719de542fdf63717fb8b38Virustotal results 17.14%
2021-01-04n/aexe af4df90789a38930e17df309cb35d20e61e9c3ceacc1935718e4958eb05fbcedVirustotal results 18.84%