URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.194/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2497395
URL: http://62.204.41.194/file.exe
URL Status:Offline
Host: 62.204.41.194
Date added:2023-01-05 06:37:10 UTC
Last online:2023-02-21 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-01-05 06:38:20 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:1 month, 17 days, 3 hours, 31 minutes Bad (down since 2023-02-21 10:10:17 UTC)
Tags:CoinMiner CoinMiner.XMRig drop-by-malware PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-06n/aexe 6e8bf74388ea7fd0920ba751b8815fc3cf8b08718062695e1860ba9afa961e12Virustotal results 41.54%RedLineStealer
2023-01-06n/aexe eb5573984eac228c2ad2009a61debb47656e3a36e30f2a5ee02d62afdf689cb1Virustotal results 37.31%CoinMiner
2023-01-06n/aexe 4a918ffe62fbbf1e196ed10be9a772a9a7889c43056ae8b3ebd16ece60a3b589Virustotal results 39.44%CoinMiner
2023-01-05n/aexe aac1a251a0246a8271d3a6274fce25e29608bd15cb1c3382232384923b6700c8Virustotal results 38.57%CoinMiner.XMRig
2023-01-05n/aexe 3970a9fddbcbafb110f7d4fa7dc63ca5508ff32007d2ab2d89ffe54a3439c0b5n/aRedLineStealer
2023-01-05n/aexe df34772d9dface6ac5f9b42d436c8d17d86c1fb918c595cdc4bcb6a3cac329ebn/a RedLineStealer
2023-01-05n/aexe d0af793e1384ddf8f41040c2de0ef1fa13a979644a4220c6f0dfb4a9c066bbd1n/aCoinMiner
2023-01-05n/aexe 0f962171e6a6219b0a1029987b166d8bd663f23f10cb53c6efe82a9bd11b6c27Virustotal results 39.44%CoinMiner
2023-01-05n/aexe a525f983338f20fb35e1fc7e2bc2995d8beddb85dba93587fa3e3cf83d5cea09n/aCoinMiner
2023-01-05n/aexe 55007e5a5bb57dbd7c9c4137cb452ef7cef8c40d268eeac4de7f40e49e8b9e25n/aRedLineStealer
2023-01-05n/aexe 6a76080cc3b34c768275c7409513aa8870b73d37fbdbe4a50ba4e14f026976f6n/aRedLineStealer