URLhaus Database

You are currently viewing the URLhaus database entry for http://190.123.44.138/rustnewest.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2142087
URL: http://190.123.44.138/rustnewest.exe
URL Status:Offline
Host: 190.123.44.138
Date added:2022-04-12 04:08:06 UTC
Last online:2022-07-14 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-04-12 04:09:06 UTC to abuse{at}panamaserver[dot]com)
Takedown time:3 months, 3 days, 11 hours, 29 minutes Bad (down since 2022-07-14 15:38:43 UTC)
Tags:exe rustystealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-09n/aexe ee323d8e241127a8150eba9b88f41d556946a124946de8d2b0241a64fbe73a01n/a 
2022-07-09n/aexe ebe30b3253b04e0095caca2991705e70815c6c80334a0ee9854f09fb67fb7cebn/a 
2022-06-25n/aexe 4e45dfd77871c853630a911e612c98be1e7966ca7b19770606107c5a7b47abf8n/a 
2022-06-10n/aexe d5cc5e35a7ea3cde97b870f91d9bc12413763eaed1506b54f7b99a2e9a4012b3n/a 
2022-06-10n/aexe e64e699f6e1e5bc4abd25a07ddbd4be1a30bf6ceb74a49b694a06818a6b0e6c2n/a 
2022-06-10n/aexe 6d36ee56fee4b0ac403c3278fdd95586ef8cd7a3441720d87ee93260f70a48bdn/a 
2022-06-10n/aexe e5f45b7c79d3ef75a00724c589bcb2d1063d383512e31ee0d5b20fe8d64e46efn/a 
2022-06-10n/aexe 051cd3b9965958aa557010e31af618b6937634a6ec595941fac11490bcff09b8n/a 
2022-06-10n/aexe 193dc6c8c075a0ad57b767b956f1b9eda6bf842253f6fb26b13c3564bff64902n/a 
2022-06-07n/aexe 7aff80f296e26572ead44608a6b4b9f7de00630ae818487f0478406c80aae446n/a 
2022-06-06n/aexe ec24699c953f9fb52dc01b72a3946ff292919540f2aa11ae5974bcaed7fefe4bn/a 
2022-04-12n/aexe dfc22ca175a54b9a52fa84e6e54b5513cb7fd762ab0fbc543e96e6bbb1cf61f1Virustotal results 28.99%RustyStealer