URLhaus Database

You are currently viewing the URLhaus database entry for http://h5-152-203-118.host.redstation.co.uk/nass.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:379143
URL: http://h5-152-203-118.host.redstation.co.uk/nass.exe
URL Status:Offline
Host: h5-152-203-118.host.redstation.co.uk
Date added:2020-06-04 13:09:06 UTC
Last online:2020-06-18 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-04 13:10:04 UTC to abuse{at}redstation[dot]com)
Takedown time:13 days, 17 hours, 14 minutes Bad (down since 2020-06-18 06:24:40 UTC)
Tags:exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-18n/aexe d1bf5b785bdb2cb6189fb1af0762dbe101571c49bfb679f7212f80b3265ce7b7n/a 
2020-06-17n/aexe 6473dd0387b598f5484812c910cea1e3929be00dcf7627fd39a69bfbd06061fbVirustotal results 36.99% NanoCore
2020-06-17n/aexe 34f1b02bdccebe61deb518957acd32c9a64ce358102db3be15ed7d46f9945004n/aNanoCore
2020-06-14n/aexe ad9b31618184bb980a5e825fcb465913f3002077043fc5e3a761653473a4dce0n/aNanoCore
2020-06-10n/aexe 0fb26042a8a31d0db10d1302875a6f44d5aa5dd369b309795172dc957eef5c4an/aNanoCore
2020-06-09n/aexe 818a6583ed6a32a51b5b576c7dba0c47fd3f243ab8016494ce6372ee6d0e91fbn/a NanoCore
2020-06-08n/aexe 21a0a09fd4ee92d560dc644492a538001f5f5c22d2c1c562a4955ac740ba66a1Virustotal results 30.00% NanoCore
2020-06-07n/aexe a2d6f81373b31670a8500a714aad457d705f07966dbadf260ec963a954061d00n/a NanoCore
2020-06-07n/aexe fb5bae3dabbf6aec4c7812eb286414b8665173fa2daabf794c571d61ae3eaa36n/a NanoCore
2020-06-04n/aexe f9614b985dcb06d9c40448e4ecf1a94ce2cd69e54f6acbeca7b6deec54aafdb3Virustotal results 32.39%NanoCore