URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.119/poka/nesto.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2516452
URL: http://62.204.41.119/poka/nesto.exe
URL Status:Offline
Host: 62.204.41.119
Date added:2023-01-23 18:36:04 UTC
Last online:2023-01-24 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-23 18:37:04 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:6 hours, 16 minutes Good (down since 2023-01-24 00:53:36 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-23n/aexe e32597cdbdb4ac78d84c5457df04c240e87a0cfdb51769789759d030da1b485cn/a RedLineStealer
2023-01-23n/aexe 94de11665f5407fc934479b14a1a30ef746e0fcd0375d5f315f8b90f57cdb262Virustotal results 35.71%RedLineStealer
2023-01-23n/aexe 17091f2207915e5697511563f3a58d4df9d56bc7b90171524499538b4d0f84c7n/a RedLineStealer
2023-01-23n/aexe 6ef6e05dded81591dc69a6d9fcd5b80f51a4495db74593ad4fbdd8be74840942n/aRedLineStealer
2023-01-23n/aexe dc61e39e78a480035981706177087d69e97668578bb51351f1f7dcdc6c89ae59Virustotal results 39.44%RedLineStealer
2023-01-23n/aexe 03640fd78685b00c87aac5f57af8f050588fbaf31235242742a03a3b788c5f84n/aRedLineStealer