URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.118/WW.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2272263
URL: http://62.204.41.118/WW.exe
URL Status:Offline
Host: 62.204.41.118
Date added:2022-08-13 06:08:05 UTC
Last online:2022-09-20 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-13 06:09:05 UTC to abuse{at}gorizontllc[dot]msk[dot]ru)
Takedown time:1 month, 7 days, 19 hours, 27 minutes Bad (down since 2022-09-20 01:36:07 UTC)
Tags:exe RecordBreaker link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-23n/aexe dd0145067f81bf5aff9a7ee7eb56c11a98a5f69a9bdbc36744919ee49890de5an/aRecordBreaker
2022-08-22n/aexe 6acec3474a2dcacc99fe7f6495d4e4e90adbb40de283054aadad2e8f91dbd115n/aRecordBreaker
2022-08-21n/aexe 57c0821fbaf17e52c36412d7fda8d79d413d53f7002689db661b8552dfc3c68an/a RedLineStealer
2022-08-20n/aexe 26aae8d9f906f877165d9b85c93579b076edfecbac5dbf5620c84f9b43fb9524n/aRecordBreaker
2022-08-19n/aexe 18696ad36e07caecddafeacb0da10199f50acc2ac45fb3531ba31aadfa337f0dn/a RecordBreaker
2022-08-16n/aexe 4c8662f187b984c7ad509d766d9514542f26ec38e8961097dd17282f0e7c6a1dn/aRedLineStealer
2022-08-15n/aexe 36d62ba86ad6bfdd5638cef785d1a06ef770d0c6594477f8a0d9244dd8eecc8an/aRecordBreaker
2022-08-15n/aexe 1fa2d39e2196269e2482a1ce406daf535d71e9d453d537899c958467beebf453n/a RedLineStealer
2022-08-14n/aexe 8bc51a634781cf0d8e4e92b66b352598dadf226a41d4554e003dc26c736eacc2n/a RecordBreaker
2022-08-13n/aexe de35d079d23fe6050502c88b2b40633f4518132df910c7100e000c4b7bcee167n/aRecordBreaker