URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.188/ano/anon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2442683
URL: http://31.41.244.188/ano/anon.exe
URL Status:Offline
Host: 31.41.244.188
Date added:2022-12-03 09:29:04 UTC
Last online:2022-12-10 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-12-03 09:30:11 UTC to dl{at}redbytes[dot]ru)
Takedown time:7 days, 0 hours, 39 minutes Bad (down since 2022-12-10 10:09:28 UTC)
Tags:dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-08n/aexe fc71ffee5ac2918dfdc256014dbb3533ca09771b17fcfcf1ed1cb3d4acbda8d5n/aRedLineStealer
2022-12-06n/aexe 7e35de071bdb96517e6aa5eeb50e037f0f44ffb2dd3fc3971ac68bd2f211a7d2n/aRedLineStealer
2022-12-05n/aexe 7d1b267f53db09f05ccf77a35c93abeb4918f76e1439cc049074845271b10ec2n/a RedLineStealer
2022-12-05n/aexe 571f691981d027a91e21c28b7eed60e6fbfafffc7d4bddc6a16421430a9ee13fn/a RedLineStealer
2022-12-05n/aexe d510a346e59953f8015eb4f8f014896f25255f28a924a749d54152ebb6cfe4dfVirustotal results 34.29% RedLineStealer
2022-12-04n/aexe 54f68753efa15d3aab3710e29006be6f5e341edce07c38eaa41abdb4bfa3c0e9n/aRedLineStealer
2022-12-03n/aexe 7e21201bce1ac386ae78ca7cd6f8b12649c61462dca2191997e9ba978f9df13fn/a RedLineStealer
2022-12-03n/aexe 73f1b7f653f05110c003b7d423d5cfc2ad59d17ccba7ce61d073256872171cc5n/a RedLineStealer
2022-12-03n/aexe 198fb046e30bf3991f698eb296859c4c5b1249ccb2f268cc4107dc472ad66d87Virustotal results 38.89%RedLineStealer