URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.119/well/desto.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2518716
URL: http://62.204.41.119/well/desto.exe
URL Status:Offline
Host: 62.204.41.119
Date added:2023-01-26 05:00:06 UTC
Last online:2023-01-26 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-01-26 05:01:05 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:12 hours, 8 minutes Good (down since 2023-01-26 17:09:35 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-26n/aexe 9f4ad24c66b7fc9f527002b181afa0ff8e7963f673cea8839beb4185c44d8937n/a RedLineStealer
2023-01-26n/aexe aa06245a00564f9db4bbd6a18eed3064cb3faaa24f0821c38c740981e56683cdn/a RedLineStealer
2023-01-26n/aexe 4e591f8bb63720bc6732735d7f5ae5030372c141632af4e253fb72add57817dfn/a RedLineStealer
2023-01-26n/aexe 8833b6adf9434402ad0f13cbb1208fd59e438ed4dbe17266959d2b3dfddc4cb9n/a RedLineStealer
2023-01-26n/aexe 4016f3de5776c7a0901112c4b306a92291f83c21c9b6ccc4de9db96f4a08eb84n/a RedLineStealer
2023-01-26n/aexe 950ed8ce45c60a61ed49d420dee6b1255978f1b5465cb890e3109c86ad876fdfn/a RedLineStealer
2023-01-26n/aexe 3e2f63bcacf67447478e2d6789fda38c78d101f079f9f9cc28edfda36306b93en/a RedLineStealer
2023-01-26n/aexe 8da09edddbd7fe649c12f5d3b6f1c793552fe8f772667114233dbb9bf71f565aVirustotal results 35.71% RedLineStealer
2023-01-26n/aexe 4895d2fbee02a90e8ffd2fc75fd7c4dc9d1b55d53a78fbcc0bb786e4597962cfn/a RedLineStealer
2023-01-26n/aexe 6163ac7700a9bca39d57cfe73b4cc93f251a164968219cb2bc8cb0944d6a7e5dn/a RedLineStealer
2023-01-26n/aexe 3fe759f4e7ada0c18ab5cd153595b0ce69f3acf3d89c249d14418d27a108982cn/a RedLineStealer
2023-01-26n/aexe fae349c67d1d6c44acdd20c396903180416b518947da90404369391d77498ddcVirustotal results 41.18% RedLineStealer