URLhaus Database

You are currently viewing the URLhaus database entry for http://3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com/WW/Setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1269087
URL: http://3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com/WW/Setup.exe
URL Status:Offline
Host: 3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com
Date added:2021-05-22 07:02:08 UTC
Last online:2021-05-29 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-05-22 07:03:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:6 days, 20 hours, 23 minutes Bad (down since 2021-05-29 03:26:49 UTC)
Tags:ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-25n/aexe 3c2fa1d04daaea31991c29bb4118c3d146a50815a033ea5ae325c3171ebdf713Virustotal results 47.83%ArkeiStealer
2021-05-24n/aexe 143f80b873592404bae9c6d3fed4467bee4795a9eebd510b6a6285dda7a2432dn/a ArkeiStealer
2021-05-24n/aexe ff4a3e44fcd1cfbbf10ac318aca7559e0c20d0563e11e8a98e21e09e97ca68d3n/aArkeiStealer
2021-05-22n/aexe 21415b4bd92f908e375ef73e62b8539724488e9372c6df980d91c01e47ebfd15Virustotal results 50.00%ArkeiStealer
2021-05-22n/aexe cb3c387163302fbf8ddb4c13e9d786c1070a4185a74bdd3faebd1649d02b2b30Virustotal results 48.57%ArkeiStealer