URLhaus Database

You are currently viewing the URLhaus database entry for http://mariobrown.net/chromiumi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1002413
URL: http://mariobrown.net/chromiumi.exe
URL Status:Offline
Host: mariobrown.net
Date added:2021-02-12 11:02:05 UTC
Last online:2022-01-10 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: de_aviation
Abuse complaint sent (?): Yes (2021-12-22 10:50:23 UTC to abuse{at}hostgator[dot]com)
Takedown time:11 months, 4 days, 22 hours, 34 minutes Bad (down since 2022-01-13 09:38:47 UTC)
Tags:ArkeiStealer link exe Formbook link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-26n/aexe 40afa1e323be151d0d7a38c72f771b0b9e909f49ddade942d4260a5e29e5ec2fn/a
2021-02-22n/aexe 989f403c14fe2ab86cb51cb4232ed7a3fc8f623ad8025e674acfa3bf45a0d917n/aFormbook
2021-02-19n/aexe 3d2bd69871c0a443d1e4c2a5ec37833dbcbce929aba368745f10d7b981a5264cn/aFormbook
2021-02-19n/aexe 52fae1ba28593ce0478042ee499f02333c1b671971c619bf7528a50ac051625an/aFormbook
2021-02-14n/aexe 5389a958986f6ceccaa9e44006852becbccabfb07f126d69e6b031227fb0b487n/aArkeiStealer
2021-02-14n/aexe d40dedd7f637a1ef9703b582a6d536469d1cf62bddc1a462a9cceeb7f9194f13n/aRedLineStealer
2021-02-12n/aexe d217032899487162688fa6c3855e13040b074de38d9c57c91b47c1190842edc2Virustotal results 49.28%RedLineStealer