URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.165/ano/anon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2486084
URL: http://62.204.41.165/ano/anon.exe
URL Status:Offline
Host: 62.204.41.165
Date added:2022-12-25 11:23:03 UTC
Last online:2022-12-28 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-12-25 11:24:06 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:3 days, 2 hours, 43 minutes Bad (down since 2022-12-28 14:07:09 UTC)
Tags:dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-28n/aexe 7b8360419ecf2c90e5dc6386e626158d83d9f08963cb10fdc273f48f31a16dedn/a RedLineStealer
2022-12-27n/aexe 153723a47df18658d161a84b3a79ba5a06f01186955a907e964230d637ef4ccdVirustotal results 66.20%RedLineStealer
2022-12-27n/aexe c79b058f49250afd715f08ea2f8ee8e50c840a9dc83e07bd6d2575f3f9270ba0Virustotal results 57.97%RedLineStealer
2022-12-26n/aexe 94e6af633045a032e33d5c7dd139f4ac6c8918f2be6bcfa2e3edf1d968473ba4n/a RedLineStealer
2022-12-25n/aexe 6986b19f5c698ed5b8ff620d17a4abe7c498a89b56425162d652d9beac305dd1Virustotal results 63.89%RedLineStealer