Raccoon Stealer - Distribution Methods
File types, delivery vectors, and hosting infrastructure used to distribute Raccoon Stealer.
Last updated: 2026-04-18
Understanding how Raccoon Stealer reaches victims is critical for prevention. This page breaks down the file types used in distribution, the hosting infrastructure serving malicious payloads, and URLs tracked by URLhaus. Data is updated daily.
What Distribution Data Tells You
Shifts in file type distribution often signal changes in delivery tactics. For example, a move from .exe to .msi files may indicate operators adapting to Windows SmartScreen or email gateway filtering. A surge in .js or .vbs files suggests script-based delivery through phishing emails. Monitoring these patterns helps you tune your email security gateway rules and endpoint protection policies to block the current delivery method before it reaches end users.
Hosting Infrastructure
The hosting data below shows which domains and servers are actively distributing Raccoon Stealer payloads. Add these to your DNS blocklists, web proxy deny rules, and firewall policies. Hosting infrastructure tends to rotate frequently as takedowns occur, so check this page regularly. All URL data is sourced from URLhaus. For hash-based indicators, see the IOC page. For sample details, see Raccoon Stealer samples.
Malicious Distribution URLs (50)
https://github.com/evan9908/Setup/raw/main/Run1123.exe https://github.com/evan9908/Setup/raw/main/file234.exe https://github.com/evan9908/setup1/raw/main/S%D0%B5tup1.exe https://github.com/evan9908/Setup/raw/main/file3333.exe https://github.com/evan9908/setup1/raw/main/lnstaIIer3.6.47.exe https://github.com/evan9908/Setup/raw/main/umr.exe https://github.com/evan9908/Setup/raw/main/Umarfile.exe https://github.com/evan9908/setup1/raw/main/setup2.exe https://github.com/evan9908/setup1/raw/main/file200h.exe https://github.com/evan9908/Setup/raw/main/Run112.exe https://github.com/evan9908/Setup/raw/main/Runfile.exe https://github.com/evan9908/Setup/raw/main/FILE2233.exe https://github.com/evan9908/setup1/raw/main/Aatxl.exe https://github.com/evan9908/Setup/raw/main/filrrr.exe https://vk.com/doc278414724_666870508?hash=4BTagkzVol6bnjALgBnHfDWhb15dXOZHQRWutZEwliX&dl=M5rxWlm6OvnOIvGOIcfdEW81w8mo6ZUU0d3ZiQM4rdc&api=1&no_preview=1#1234 http://doodlesz.app/Binary.exe https://vk.com/doc278414724_666829725?hash=qzaHx0YlDB12LoECl1K8CFRZBNJ0wccMz3tfobfKIU0&dl=V8FYDIT8s4WTeucV5o21YcwJJyMtrJFSprR3FlVfRYg&api=1&no_preview=1#1234 http://doodlesz.app/Morning.exe http://193.233.132.17/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://45.15.156.26/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://195.20.16.35/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll https://vk.com/doc26060933_667544539?hash=wU0LmcDUgWyN1ZcNDJrEhPYblOsZzP1L88mZrmsb6Xc&dl=Gz6A04xbKOSfev3zf7pWd0GaYFvSioG5s5b1OB8QbFH&api=1&no_preview=1#telegram https://vk.com/doc26060933_667420499?hash=hlUJdOwZjE8571XmogQucbSZyiziRlWeMjQcIG1V4ys&dl=1ZBJJuMHSETLeLyrtfp6OjQSvy2GobUEeHu2UsBzr2g&api=1&no_preview=1#try https://protect.line.pm/WindowsUpdates/KB5020613.exe https://filehosting.linkpc.net/ch4cvanhvvczjl06ea54oj7z95c6tmzd/original1.exe https://connectivity-check.linkpc.net/ddyetjgr0fshfd3ojh6oxte4pfxgz6xx/svchost.exe http://128.140.101.125/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll http://94.142.138.221/file/name.exe https://vk.com/doc801981293_667932148?hash=qDkXeRt6iOUx4359rV0YzPCJLHTvqLQciH6GiJqIBqg&dl=4rySXFmh26SemrnHj2C8pb0cgHJ82YSfX78sv47pj4T&api=1&no_preview=1#v2 https://vk.com/doc808950829_663370595?hash=shZybDXhXJCDtBsHz2eiK3Q7w1rFuIPnKZTPGYiBXZP&dl=sIEAZ80JfTGDtIXWtsPBVihBgsi8wYWRGVMfh9V3Cgg&api=1&no_preview=1#house http://146.70.86.20/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://79.137.203.217/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://94.142.138.246/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://5.255.127.159/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://77.91.73.11:2705/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://94.142.138.103/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://217.138.215.87/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://5.42.64.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://5.42.65.18/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://79.137.206.76/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://94.142.138.31/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://78.46.187.251:2706/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://78.46.248.198/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll http://5.252.177.107/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll https://vk.com/doc797927207_660166827?hash=S9d1LRpKkBqqaTTkzFYojvcJ3L3a8zzgjeJXmhRuRB8&dl=G44TOOJSG4ZDANY:1683746472:NUGgowD5mgwGUbp3JvSIkoB9wFYDzijcgoJB26mzagH&api=1&no_preview=1#orig5 http://77.91.86.211/123.exe https://vk.com/doc797927207_659869708?hash=QlwRceOu0t5mc6ZA6B6CPb76K5zt4EH554nPjch6G94&dl=G44TOOJSG4ZDANY:1683266431:z2wWeeJx93d0wb6BBQhZGEZdwhDsgQ4mzaZeUpniZCT&api=1&no_preview=1 https://vk.com/doc791620691_662628941?hash=5VF027LHEWTmSZU0J4O1UGJBUszztj9IkqXvfCZOZe8&dl=G44TCNRSGA3DSMI:1682097488:tPSU7pkqh4lzBVJ6FHl0cAkE4XzuQ5TZrHTtNIg0kGL&api=1&no_preview=1#ws2eu https://download2336.mediafire.com/xd4l52cucgygwjeNVws8SmLGC9fGEZ7pPDUTfCzDowGB4p9wGqQcaURvYT0m46YP96Hi_kTur5kNXTAo6NlmNOEQwleXgzbI/3f7z7b353eotsgi/9475099.rar https://transfer.sh/get/dtxCng/BlenderCrack.rar
Source: URLhaus (abuse.ch). Updated: 2026-04-18
Hosting Infrastructure
| Host | URLs |
|---|---|
| github.com | 14 |
| vk.com | 9 |
| doodlesz.app | 2 |
| 193.233.132.17 | 1 |
| 45.15.156.26 | 1 |
| 195.20.16.35 | 1 |
| protect.line.pm | 1 |
| filehosting.linkpc.net | 1 |
| connectivity-check.linkpc.net | 1 |
| 128.140.101.125 | 1 |
| 94.142.138.221 | 1 |
| 146.70.86.20 | 1 |
| 79.137.203.217 | 1 |
| 94.142.138.246 | 1 |
| 5.255.127.159 | 1 |
| 77.91.73.11 | 1 |
| 94.142.138.103 | 1 |
| 217.138.215.87 | 1 |
| 5.42.64.13 | 1 |
| 5.42.65.18 | 1 |