URLhaus Database

You are currently viewing the URLhaus database entry for http://paperships.top/bestof/gfers.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:998432
URL: http://paperships.top/bestof/gfers.exe
URL Status:Offline
Host: paperships.top
Date added:2021-02-10 07:38:05 UTC
Last online:2021-02-26 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-10 07:40:06 UTC to ost{at}sbcloud[dot]ru)
Takedown time:16 days, 14 hours, 36 minutes Bad (down since 2021-02-26 22:16:53 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-26n/aexe c5d0e2036267482dcbf360b0f2be1dba1ac73bf7f1c8512a4816fc6e607bf485n/a RedLineStealer
2021-02-25n/aexe 3a77d697b35b9de741ac611c904aca942a17d4ac8f786f4f9b9532dec277a8f6n/aRedLineStealer
2021-02-23n/aexe 4ef2301fc3da6b681932cd7a7d32fa6a86800651976a1b9a847864a65f6234f8n/aRedLineStealer
2021-02-22n/aexe 676593610aafb444bd3b06028cbe14c0f1bb08d621da061609436d0afbe536fbn/aRedLineStealer
2021-02-22n/aexe 6fc478619e492f7c687bdff2235a57206f867c0601e22301480202a9c0ceb16bVirustotal results 46.38% RedLineStealer
2021-02-19n/aexe 3de9238c143c51c930d09f9b28182a9f9208eb8db6245c7fc16fce67b13f34fcn/a RedLineStealer
2021-02-19n/aexe 19890d123eb7e4f772159aeb1c68a42785a5bcb2a25da044c21656fb83b4d530n/a RedLineStealer
2021-02-19n/aexe fa8288121fc03ad692564b12fa8483fe51f4086910d748db2be43eebb6a67de2n/a RedLineStealer
2021-02-18n/aexe 0e09d3298aae4a2a440ae32321a8f6db607e9cb072156b17eb8fb12b212c1cf6n/aRedLineStealer
2021-02-17n/aexe ddd810853f9fa4626060db340eaf5c38b614b81be0dc05f92c0f5356431bc9c5n/aRedLineStealer
2021-02-16n/aexe 1cc5cd7cbf758f41dedcf4f9accd9af082d547437644a1e8afb2195698c34dden/aRedLineStealer
2021-02-14n/aexe e99ab798099b3c352427b7808b0a2c7e73854aaeb34001f17852e288af321f6cn/aRedLineStealer
2021-02-13n/aexe 59c716406e823c0c18ee285114413fb69babf813725be46e6bafa5fdf4cfbcf3n/a RedLineStealer
2021-02-12n/aexe 1ad35ecffd662312ffa048ae8b85344267ebdd6d5c3be375c99b84c57d3ef117n/a RedLineStealer
2021-02-11n/aexe 808be962b671de3c658a363c3ca14ea5181d3669f0a23f0263a175e9416daab5n/aRedLineStealer
2021-02-10n/aexe b6255ccb6a0c4843452827ec54f6f041a3285f3042668d1ba4f7593f733d420fn/aRedLineStealer
2021-02-10n/aexe e0e1df2e713258532e08c09458ad6f5e50163b1e7c9c1f1446f0023c4e479befn/aRedLineStealer