URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.23/file/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2624532
URL: http://62.204.41.23/file/file.exe
URL Status:Offline
Host: 62.204.41.23
Date added:2023-05-04 13:28:05 UTC
Last online:2023-05-14 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-05-04 13:29:05 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:10 days, 1 hours, 0 minutes Bad (down since 2023-05-14 14:29:58 UTC)
Tags:CoinMiner dropped-by-PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13n/aexe 0f8168d7e2e321127922e20ffe0069561cd369e8e46dcd6e0e86e38dbfd31bc9Virustotal results 50.70% RedLineStealer
2023-05-13n/aexe 7d020d7d0d68281b46a56287d1e9a4a2922ae8fa4ac090a863ca97d923ab9572Virustotal results 46.48% RedLineStealer
2023-05-12n/aexe 917f0c9d74330677207bc22b6c27d4087f6dfef39b69ff598925a15d6e58b4den/aRedLineStealer
2023-05-12n/aexe 712f4d08ad4db1fb658d8206cee6a00f4024fd4ef5de8de0dfbe0d98779f9f86n/aRedLineStealer
2023-05-12n/aexe 1414bfe5348a01c068be32ab8f616f91fe58eba7f9c60d5e685769fb3d711261n/aRedLineStealer
2023-05-12n/aexe cccee6f44a526ef597d95773f70b51489c30745e012fb3ea230756839616397dn/a RedLineStealer
2023-05-11n/aexe e7fca093b926acba3bc60a2d4079925f30e4e220fc2244847cb4e9ab480da59bn/aRedLineStealer
2023-05-11n/aexe 8fdff5872bb83fc7f63257d88ffe2116453a407172bf86a282b674fe6d63126bn/a RedLineStealer
2023-05-11n/aexe c7e8a518b38ed239f30477e175b128475016cc22bdf0e8baca7ef68a57a0f75en/a RedLineStealer
2023-05-10n/aexe 036413639106d4aab39e6c0507fe9e9ed58bdb2ec21612bc7290526bd11756b9n/a RedLineStealer
2023-05-10n/aexe 0fc03c83991a6536ea19827f36b9293e26fa5d16b0a9ced638a8c11ab51c5248Virustotal results 26.47%RedLineStealer
2023-05-10n/aexe f9cfd4cc7fd814ed426c494b0d79ad26c7e0c2763c2cf5da86974dcf1fdda6efn/aRedLineStealer
2023-05-09n/aexe 08317611732baf1318f2f4344b805765a0e7e35116098bc4c1f999952495bdf4n/aRedLineStealer
2023-05-08n/aexe 16d4e713b6970d966dc0df74b54d3d974016649ac65fd2188ee9d35c679ef13bn/aRedLineStealer
2023-05-08n/aexe e265bf051d26a8e12e05c035421e0070518f632d25f93e6f4b2b8b82e24a8e87n/a RedLineStealer
2023-05-07n/aexe 05304efb0d6d7f4f5d5bea50cb9e1dc7c2034bfdd374ca737f604f1ec78cac68Virustotal results 22.86%RedLineStealer
2023-05-07n/aexe 2073e60238669378edde068984829664197b70d887e0b0a50fa4cbc5b60a673fVirustotal results 17.39% RedLineStealer
2023-05-06n/aexe e0e267a1da22b796f4f8a7b84a81d0f0a461183cdc03d267a75e34d9fc497ccdVirustotal results 27.14%RedLineStealer
2023-05-05n/aexe ac3af6bd3139c444e8e146a6d48c110ae33c09d23c84b7b02f3d7af9eaa49c84Virustotal results 27.54%CoinMiner
2023-05-05n/aexe 3dbfc85922adcc72d86d8c50d0e027efeb71bc9b0b4f8c7bba7be5348a7d0d5dn/aRedLineStealer
2023-05-04n/aexe d540f75897495102dd30eaa924623ac40415e8a716bdcbadf7d7c9a00feb5c97Virustotal results 28.57%RedLineStealer