URLhaus Database

You are currently viewing the URLhaus database entry for https://niancr.world/java/centos/33940/10032b.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2561883
URL: https://niancr.world/java/centos/33940/10032b.exe
URL Status:Offline
Host: niancr.world
Date added:2023-03-07 16:49:06 UTC
Last online:2023-03-07 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-03-07 16:50:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 17 hours, 14 minutes Poor (down since 2023-03-09 10:04:21 UTC)
Tags:Amadey dropped-by-PrivateLoader RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-09n/aexe e79f6b647f3dea75b425804ecdcd7e42c966a7168cf47228b94c252da7eee4a6n/a RedLineStealer
2023-03-09n/aexe 89f41404ab215bf17a4bcc91d16a45521b7b9ef84ea4a0415fb650048bee6590n/a Amadey
2023-03-09n/aexe 6307345617eee657d55b05d3b9696a8569220f16eb6d4a2092eb07bc25cf00f4n/a RedLineStealer
2023-03-09n/aexe 412e681eb695cc92d63a15d08040aba1eb2d64a7e16b829aedde95eba9e793afVirustotal results 37.68% RedLineStealer
2023-03-09n/aexe ff1f02ee600cec6dae576aaeebd75f8f8c696753eb56a916603cc8e1dd8f9c54n/a RedLineStealer
2023-03-09n/aexe 89b79d34567c98670363e66c8ff39b3b076693553744ed122e28143b0b0b0c79n/a RedLineStealer
2023-03-08n/aexe 80fdacf20dafe660e7ea195411ad2595860259cd140f93e1376d04932d9a9765Virustotal results 31.82%RedLineStealer
2023-03-08n/aexe 3a1e6d5f76e8d2cc7c78dabeb6bfbffc298324fa712a55d137a1e095f762dacdVirustotal results 36.23%Amadey
2023-03-08n/aexe 7c98bc665b12e5b4602947e7f6eab31e12497516e2888e0edbd7c6e9dfd3ec49Virustotal results 36.23%RedLineStealer
2023-03-08n/aexe d479fbc3b01161bcdbfa1a314df42b29947ba1c115139aa93cb03997f4deb864Virustotal results 34.78%Amadey
2023-03-08n/aexe a12518fcdbf4356e37cb65eed176d260f460dd66cd0ff2ac5f22fcd90bad8868n/aRedLineStealer
2023-03-08n/aexe 564a9dd018dc5d85c1e8406409196f91184ae2ef342115733c7a666eabf44567n/aRedLineStealer
2023-03-08n/aexe 012246d33d0db647d7d358792ca9610d561f0cfdbb7b173966842d93ad4af725Virustotal results 36.76%RedLineStealer
2023-03-08n/aexe 84acf5932e36ea7bb2c94b9c634c5b34b5564ec881596ce0efae3a9066301eaeVirustotal results 36.76%RedLineStealer
2023-03-08n/aexe 073cfa9c393ec523939794ed92996a25d4693a936db98eefa17744a44946eb70n/aRedLineStealer
2023-03-08n/aexe fb355965642d20a78b7a471b60f0d6e2ec1f6ed6ec3560665244c57a506cd38dn/aRedLineStealer
2023-03-08n/aexe fceb3b6d7ea0f7d13e45f8aad5f61490f8ab9b095b1a5872aa370fec58b03715Virustotal results 43.28%Amadey
2023-03-08n/aexe e59ca3b68b66ebc9e0a7e47c38dbce2a1f1de6a48d9c151f4e1c3072d7da428cn/aRedLineStealer
2023-03-08n/aexe 40f45b29f62c96640b2a63dd7ac82af790691772ee6de48e46a243e78ee428bfn/aRedLineStealer
2023-03-08n/aexe e6c6569a66256fc40bcbc3ded95a27998f5d1b0387f91099e9e97cdad4bdeecdn/aAmadey
2023-03-07n/aexe a7a9f5effd1031c48c4abf0eabda7a776945b6f41eeaec5a009a305ca000a44dn/aAmadey
2023-03-07n/aexe da67b579a79711316bea01386826c26dd956ce8cf31695d7391a243a7588143an/aRedLineStealer
2023-03-07n/aexe a2d2e85551546b62fa238f23860cff382bcb3dfaff891d070105a01ba5c15626n/aAmadey
2023-03-07n/aexe f0ec980108157002c8ca92507a2caa1f9a2cfa548959c7b1a2533ab7030966eeVirustotal results 36.23%RedLineStealer
2023-03-07n/aexe f400e7797e267ecf94f95740aff8b443ff77f47f5bf434ad9c301bce119c5641n/aRedLineStealer