samuelelena.co
Classification: Suspicious
samuelelena.co is a suspicious hostname. Linked to Redline Stealer, Ransomhub malware. Reported by 2 threat sources, last seen 2025-04-04.
Current activity
- Offline β no longer resolving. Last online 2025-08-31 20:53:48.
- Malware distribution β This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: REDLINE STEALER (S1240) RANSOMHUB (S1212)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Ransomhub | Maltiverse Threat Observatory | 2024-11-01 14:51:52 | 2025-04-04 00:40:06 | S1212 RansomHub | |
| Generic Malware | Maltiverse Threat Observatory | 2024-11-01 14:59:37 | 2024-11-01 15:14:20 | ||
| RedLine Stealer | ThreatFox Abuse.ch | 2023-09-16 08:56:31 | 2023-09-18 08:18:18 | malicious-activity | S1240 RedLine Stealer |
IP addresses resolved by this hostname
- 34.70.133.246 (2024-10-29 17:05:00)
- 35.225.36.88 (2024-10-29 17:05:00)
- 104.155.138.21 (2024-11-07 08:18:09)
- 107.178.223.183 (2024-11-07 08:18:09)
- 50.17.207.246 (2024-09-27 01:02:23)
- 23.22.122.205 (2024-09-27 01:02:23)
- 2600:1900:40d1:346:8000:2:8da2:678e (2025-07-01 04:00:10)
- 34.159.223.43 (2025-07-01 04:00:10)
- 2600:1900:4000:189e:8000:2:8da2:678e (2025-07-01 04:00:10)
- 2600:1900:4001:96e:8000:0:8da2:678e (2025-07-03 12:00:06)
- 34.41.139.193 (2025-07-09 08:00:08)
- 2600:1900:4001:96e:8000:1:8da2:678e (2025-07-09 08:00:08)
Whois information
- AS name
- AS396982 Google LLC
- Domain
- samuelelena.co
- TLD
- co
- DNSSEC
- ['unsigned']
- Nameservers
- ns1.hwrn.net, ns2.hwrn.net
- Registrant
- Dynadot Inc
- Address
- REDACTED FOR PRIVACY
- City
- REDACTED FOR PRIVACY
- State
- California
- Country
- US β United States πΊπΈ
- Contact email
- [email protected]
- Domain created
- 2024-10-02 18:29:43
- Domain expires
- 2025-10-02 18:29:43
- First indexed
- 2023-09-16 09:17:03
- Last updated
- 2026-08-26 10:45:55