URLhaus Database

You are currently viewing the URLhaus database entry for http://closehub.ru/files/%EF%BB%BF259_1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2207486
URL: http://closehub.ru/files/%EF%BB%BF259_1.exe
URL Status:Offline
Host: closehub.ru
Date added:2022-05-23 06:33:04 UTC
Last online:2022-11-29 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-11-19 18:46:14 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 months, 27 days, 20 hours, 9 minutes Bad (down since 2023-01-16 02:43:21 UTC)
Tags:32 CoinMiner exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-20n/aexe ed6aa3b45531b523549ea2e3214d589d36c27171d774aebf8d7c7635f902572dn/a 
2022-11-10n/aexe 20b5d82a4dd11d6c7bdc61c16e64df4baa19458186f6daf7865913a444c06a4en/a 
2022-08-15n/aexe 101c91416e5e3af343cfc511395be86c4cf63f4306587418cd43317339816fddn/a 
2022-07-26n/aexe afa216bf217b0e8a618ca168f67e280fa55a8de00472f7af3c1b05ddba154a21n/a RedLineStealer
2022-07-07n/aexe 87f6dc46e91c26a02766a3051ebcd7ce0b23400d6751c3f7ec1a8b8a53c03d22n/a RedLineStealer
2022-05-23n/aexe 32dbd23da3165e24cca4714f1b822d02f7056fb7bf21e687ae5506109f223b3fVirustotal results 41.18%CoinMiner