URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.251/mohna/nocr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2536778
URL: http://62.204.41.251/mohna/nocr.exe
URL Status:Offline
Host: 62.204.41.251
Date added:2023-02-11 08:36:05 UTC
Last online:2023-02-23 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-11 08:37:08 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:12 days, 10 hours, 54 minutes Bad (down since 2023-02-23 19:32:07 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-22n/aexe 4e3d2a871569ffa5d2d7a5129029758cddf7715ba9afb5d8c96492d5e44c2dd6n/a RedLineStealer
2023-02-17n/aexe 1ee43fcc72b32fe38b4cc917c4d1cefe7f2890c6ed6d51488fc5b3cd6b6eab9eVirustotal results 69.01% RedLineStealer
2023-02-16n/aexe 38a3186a175d2d3a7f9216f6b8df67264f1a38d320547b7016d4d2f9ad2b845en/a RedLineStealer
2023-02-14n/aexe ce360295ca7fcc1a1c2b47a604305c67ab41358770edbd769a6a44aa635c2fd0n/a RedLineStealer
2023-02-12n/aexe f281aafa876847194d635feddb06b11295249cc4bcf940d5246bdb5938410881Virustotal results 66.20% RedLineStealer
2023-02-11n/aexe 0cca99711baf600eb030bbfcf279faf74c564084e733df3d9e98bea3e4e2f45fVirustotal results 78.87%RedLineStealer