URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.251/dora/fuka.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2536779
URL: http://62.204.41.251/dora/fuka.exe
URL Status:Offline
Host: 62.204.41.251
Date added:2023-02-11 08:36:05 UTC
Last online:2023-03-29 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-11 08:37:08 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:1 month, 15 days, 19 hours, 3 minutes Bad (down since 2023-03-29 03:40:36 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-24n/aexe f71c9a09d55770450c713d647da633d1bf58d5e4ade727c4a41e36cb705abf37n/a RedLineStealer
2023-02-21n/aexe 8a07fc51578589686a864b2d74ac3c1b02a9ceee8f8a20d432832228d9665459n/aRedLineStealer
2023-02-20n/aexe 2fb9f641ca9803691921d773a0ea160513bcc34ac32ebb4e9f9551b05847536en/a RedLineStealer
2023-02-18n/aexe 9c7a3fcd95e07c795991d968f023e251e1b19033acbdeff99a2534ed804b283bn/a RedLineStealer
2023-02-17n/aexe 35bf034217a7e519626a2e1f7d1627322ebb31f9fa8e839eafdf7ae2cde977ben/aRedLineStealer
2023-02-14n/aexe 1a09ce1cb64219a5d88e57845dc9ba6631efa06fccc8867ccf94eb132947563eVirustotal results 67.61%RedLineStealer
2023-02-11n/aexe e6d9ee8ab0ea2ade6e5a9481d8f0f921427ec6919b1b48c6067570fde270736bVirustotal results 76.06%RedLineStealer