URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.145/ano/clim.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2488586
URL: http://62.204.41.145/ano/clim.exe
URL Status:Offline
Host: 62.204.41.145
Date added:2022-12-27 21:27:10 UTC
Last online:2023-01-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-12-27 21:28:05 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:12 days, 0 hours, 23 minutes Bad (down since 2023-01-08 21:51:25 UTC)
Tags:CoinMiner dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-06n/aexe 6147a8896c15a367f51c6eff3309f58196d72efc6ff756e4e55ff74cc9d26bfbn/aCoinMiner
2023-01-06n/aexe 83e803bf3fc4a10e3131ba57f105eec47a505833101f0b7e2ab109b9665925c7n/a RedLineStealer
2022-12-31n/aexe 958bcb5e7468319ce0993304c59f478dbd20501fad251e81b968e5023450564cn/a CoinMiner
2022-12-30n/aexe 37039db3666b741d1a65031170e510f509cf7a9b526dd225af7e0ce754e958ebn/aCoinMiner
2022-12-29n/aexe e19e66572c3b7f2d7c0c84dff04dc7f6f83b7d3d8a5d6a92891e01871086ec68n/aCoinMiner
2022-12-29n/aexe 14a4c5f94168cf0b8120620cf74b943ef1f56b69034cb3151e3e405ec865d049n/aCoinMiner
2022-12-28n/aexe 5af61221043abb4eba8c526ecd86fde4ad33e32306e52a8fa5acff90300a4a6en/aCoinMiner
2022-12-28n/aexe ca806e4d3bbc3a540d1bb64f18fee3fbabba1cd40d560c48af92bc389ad9e941n/a
2022-12-28n/aexe 0047d862c8066ba8e1cb1b84aa9a394453046c22e71aa0c435a2c30f5fe2eb9dn/a RedLineStealer
2022-12-28n/aexe 000963464f2db00a7d8750c8b9115ae1a4a0b460ab6ac63b7e6452127a1c869en/aCoinMiner
2022-12-27n/aexe bb663ba471aaf77d92dd862523ccf932264f9ecc0a2b5add42599299b6c83fd6Virustotal results 37.50%CoinMiner