URLhaus Database

You are currently viewing the URLhaus database entry for http://45.15.143.191/files/file3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1247378
URL: http://45.15.143.191/files/file3.exe
URL Status:Offline
Host: 45.15.143.191
Date added:2021-05-17 13:39:04 UTC
Last online:2021-05-25 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: 0x746f6d6669
Abuse complaint sent (?): Yes (2021-05-17 13:40:03 UTC to abuse{at}dedipath[dot]com)
Takedown time:7 days, 13 hours, 1 minutes Bad (down since 2021-05-25 02:41:50 UTC)
Tags:ArkeiStealer link FickerStealer link gcleaner link RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-24n/aexe 8ef8d0f8cd7a8a21e3a21d6d453671c26448e467fb83a6c86f7ad972c43847d6Virustotal results 44.93%RedLineStealer
2021-05-24n/aexe 1598f99229e1c6eb9542e249d53a4751832e429d4f9ca11f252d59a20fa34ba5n/a RaccoonStealer
2021-05-24n/aexe a17bb3e305532ac8e6dd2785ae50cf5f18a3de6a9ea2a4b75ea841b66ba94509n/aGCleaner
2021-05-23n/aexe a5e79ae2f930e6ae8ba7057f14c5b96a7962c0720ddd040a655e59c8dae4b959n/aRedLineStealer
2021-05-22n/aexe 43eb032fa36ff0b40420df7d5fa121910ec02ba7ba03581a5a7188939ddc24eeVirustotal results 40.00%ArkeiStealer
2021-05-20n/aexe 11f1345ee856c98d60b582038559f98568bba03e9317d6ec09bc3ece4f04c422Virustotal results 32.84% FickerStealer
2021-05-19n/aexe 0d005307165e538be5f41e688a79fa15fe2098258ffa5b69a88869bbb73e2addVirustotal results 29.41% 
2021-05-18n/aexe d6deabd0461b8e011d8cb2dd90a6b11de93fb18f82cfed00816b85a5d444744fn/a RedLineStealer
2021-05-17n/aexe dab1943418275fa0a684702d291fa2fd693bebc19b99f7af9ad8dc3dd0a47cb5Virustotal results 36.23%FickerStealer