URLhaus Database

You are currently viewing the URLhaus database entry for http://107.182.129.251/WW/ruzki.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2276317
URL: http://107.182.129.251/WW/ruzki.exe
URL Status:Offline
Host: 107.182.129.251
Date added:2022-08-24 05:54:05 UTC
Last online:2022-12-22 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-08-24 05:55:06 UTC to abuse{at}serverion[dot]com)
Takedown time:4 months, 0 days, 2 hours, 32 minutes Bad (down since 2022-12-22 08:27:38 UTC)
Tags:dropby PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-10n/aexe 2a20db6840dbf8c52d0cbf51543421a246cb6a718d8c1de7b64643b5b3d23b00n/a 
2022-09-30n/aexe 6fad48e6231fd241dce8e3285efc3a1c2dd33fcf165e3994fb7703bf6252c3ebn/a 
2022-09-17n/aexe 644c791d1c62f458cfd42b27fa1292b403c172c40b4458cc219c6d938975760bn/a 
2022-08-24n/aexe 8ebb6a267127e1437a1fea7a658729c80947a433b5e9a999f82766b7986bab0bVirustotal results 39.44%RedLineStealer