URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.251/orta/dubna.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2535039
URL: http://62.204.41.251/orta/dubna.exe
URL Status:Offline
Host: 62.204.41.251
Date added:2023-02-09 12:58:04 UTC
Last online:2023-03-29 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-09 12:59:04 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:1 month, 17 days, 13 hours, 43 minutes Bad (down since 2023-03-29 02:43:02 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-24n/aexe 9a01b1bf404479dde51650769ed7c43431cb00c618f8bf5444d9cbc60946d689n/a RedLineStealer
2023-02-21n/aexe 7458552d7c845c70b436f63923f8d78954f6fed891be8aa275bf8a5a5bc7af3bVirustotal results 67.14%RedLineStealer
2023-02-20n/aexe b6deee8ac2de2c2bdb8962008c6ab542357ab80d9074cae440bb2dcfef8b4d44n/a RedLineStealer
2023-02-18n/aexe f39bdc423133d37186ba4eaf1f6da21c375a2b84ae1da4f9e91afc3dd0b04683n/a RedLineStealer
2023-02-17n/aexe c531095f91211aea5e7ed61228c557ea1718605e8840e9ca61e3e652d4634d2dn/aRedLineStealer
2023-02-14n/aexe dc28c9d9ab3f30222ed59f3991c5981bec40604e725ece488d8599eef917a7b3Virustotal results 63.38%RedLineStealer
2023-02-11n/aexe c41dc7f6cc752595337cd7f209f923b43b061b201c6ab4dc02151afb90cd66e2Virustotal results 74.65% RedLineStealer
2023-02-09n/aexe a6416ca607f03e7d02dd9c8b546113c71f421c0ba8438dafb941d25f8cf2c9e6n/aRedLineStealer