URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.245/moytru/hala.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2539943
URL: http://62.204.41.245/moytru/hala.exe
URL Status:Offline
Host: 62.204.41.245
Date added:2023-02-14 16:40:07 UTC
Last online:2023-02-22 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-14 16:41:06 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:8 days, 3 hours, 29 minutes Bad (down since 2023-02-22 20:10:32 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-14n/aexe cf169aa5a037cf9872e83a0afaec0d754782e3031b97c20ab82d5a4cc236cd84Virustotal results 57.75%RedLineStealer
2023-02-14n/aexe 96f65fdd17e0597a18fd472faa0b80452ce17a85ec2bae585131929f905267edn/aRedLineStealer
2023-02-14n/aexe 3630b9fd9d3d3f24c1b3116118f7068b48c74201938a8fdfaa4d32116d383aben/aRedLineStealer
2023-02-14n/aexe a73a1a0b55c18085c146c9b1fcbfb5e8e722302a97b7b1d33c37ed9a15d6e991n/aRedLineStealer
2023-02-14n/aexe 5a85af3e3d8de4f9d8ee3f0e7077cc5560731b0d52caf1495c5332b16f157eban/aRedLineStealer
2023-02-14n/aexe 733a22a88cd20d924eb527f310048a6fe8edc8674ff3187557c320bbb895235dn/aRedLineStealer
2023-02-14n/aexe 2e42dcb63ce6ab8e0c985e0e9c3b40a5ecbbe798b0a6c477cd39c123344c7d2bn/aRedLineStealer
2023-02-14n/aexe 222c0a8b5aa876d94d3614dca3591b889090bd9301178cd4ec8baa063cf76271n/aRedLineStealer
2023-02-14n/aexe 6922550edceae316a1034c8ecdcba9b048b6d33961cb224e8ee75af09da431c1n/aRedLineStealer