URLhaus Database

You are currently viewing the URLhaus database entry for http://bernhardtroost.top/nerino.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2587179
URL: http://bernhardtroost.top/nerino.exe
URL Status:Offline
Host: bernhardtroost.top
Date added:2023-03-27 05:34:06 UTC
Last online:2023-03-27 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: crep1x
Abuse complaint sent (?): Yes (2023-03-27 05:35:10 UTC to abuse{at}cloudx[dot]ru)
Takedown time:15 hours, 20 minutes Good (down since 2023-03-27 20:56:05 UTC)
Tags:Stealc stealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-27n/aexe cddf6506295f30fbaeb3a7111412a1a58b59a0ae25676515a6aae4d1f8eb057fn/a Stealc
2023-03-27n/aexe db62d2e44ea8b9c14f3ce497ca0b657fd51104ce48a16d1f6ae3af71f586d07cn/aStealc
2023-03-27n/aexe 87314838047125700260d065feaef4202abb6dd60dba26890ce8a759aef3079eVirustotal results 43.28%Stealc
2023-03-27n/aexe d25cffb62ca775b060887e2943ddfafe2b183f038e2e416b637fe51853185dddVirustotal results 47.83%Stealc
2023-03-27n/aexe 12a1a530485fcada38ae6dd941f11aef6648d635e6b39662e2ab7b882914772dn/a Stealc
2023-03-27n/aexe 7c2aa658f66060d41d5871618c6c1de68ce61e72fbe19b63bb56e8075b678fedn/a Stealc
2023-03-27n/aexe 7ec8478c6106ce42a1e953872234ef2f2eb812b0bc5dafdc9fcd17f905322d09n/a Stealc
2023-03-27n/aexe 5dfb1e4c32c994d72e8a7553a3bde80ba2e35e5dc4c38553effa8331849297a9n/aStealc
2023-03-27n/aexe f639530345c52597fc8d4f6ccc98b71f03088a0c330a7df97cf4e3099da918b1n/aStealc