URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.173/ano/anon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2485558
URL: http://31.41.244.173/ano/anon.exe
URL Status:Offline
Host: 31.41.244.173
Date added:2022-12-25 00:24:09 UTC
Last online:2022-12-29 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-12-25 00:25:06 UTC to dl{at}redbytes[dot]ru)
Takedown time:4 days, 16 hours, 14 minutes Bad (down since 2022-12-29 16:40:01 UTC)
Tags:dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-28n/aexe 6c761dcdf40ed30cce870368d5722120ec0c893d89142ae7f4e5efa9eeefe949n/a RedLineStealer
2022-12-28n/aexe eeb900ee8782e3f2137cd058f303340c4011eda840d0140176c5451344316301n/a RedLineStealer
2022-12-28n/aexe 7b8360419ecf2c90e5dc6386e626158d83d9f08963cb10fdc273f48f31a16dedn/a RedLineStealer
2022-12-27n/aexe 153723a47df18658d161a84b3a79ba5a06f01186955a907e964230d637ef4ccdVirustotal results 66.20%RedLineStealer
2022-12-27n/aexe c79b058f49250afd715f08ea2f8ee8e50c840a9dc83e07bd6d2575f3f9270ba0n/aRedLineStealer
2022-12-26n/aexe 94e6af633045a032e33d5c7dd139f4ac6c8918f2be6bcfa2e3edf1d968473ba4Virustotal results 61.11% RedLineStealer
2022-12-25n/aexe 6986b19f5c698ed5b8ff620d17a4abe7c498a89b56425162d652d9beac305dd1n/aRedLineStealer
2022-12-25n/aexe 4959ecdbe225976635a4be74548d955ed181ba257fb7c60bff4161d949eeb226Virustotal results 62.50%RedLineStealer