URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.87/file/lega.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2589183
URL: http://62.204.41.87/file/lega.exe
URL Status:Offline
Host: 62.204.41.87
Date added:2023-03-28 17:42:07 UTC
Last online:2023-03-29 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-28 17:43:05 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:16 hours, 6 minutes Good (down since 2023-03-29 09:49:39 UTC)
Tags:Amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-29n/aexe 2d503938677a61b00bb76de8149406b0500d96c5511fd4e3515d6d7695ab0da8n/a Amadey
2023-03-29n/aexe 3784784a65484e029f7acdf3548d94e36ced79b2186c6e9d5311380c8cf4828an/a RedLineStealer
2023-03-29n/aexe b44c5aebf9ab96deae0bde4817b045db33ff0b757189e1c10ee0d369033e1a1dn/a RedLineStealer
2023-03-29n/aexe 5f6a61323b1ddd6f0964071a092203242a5e5bcfe2dded0249d1a898d03b52bfn/a RedLineStealer
2023-03-29n/aexe 966c05b7cc0dc7ad839d55332ef422c0362107866e6a16ee07e96de3f4d78212n/a RedLineStealer
2023-03-29n/aexe ebe674b53443480965e1f41985b414caba6a12e3c5d03e9532e1fb8c03fa57e9n/a RedLineStealer
2023-03-28n/aexe 8770ef0b89512a13076550061c19838e6c7225a29f694f8ee67b2351d71a96d6n/a RedLineStealer
2023-03-28n/aexe c4998f9d98c372ea176e2e5bbc3d71bac17a4741337f159156894c9dd193a476n/a RedLineStealer
2023-03-28n/aexe ef04eebb3d083ba66be21157aab5f3199e617cf01093d668ba8ac7df67ee5658n/a Amadey
2023-03-28n/aexe 507ee3d3b0b807d5466ce3a42090d0da1eda1d21072da067f3844c2b2d904ee4n/a RedLineStealer
2023-03-28n/aexe 6f884d2f20c49799cdcf67d604553a3fa1dca599598410b78789a660554df243n/aRedLineStealer