URLhaus Database

You are currently viewing the URLhaus database entry for http://3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com/USA/Setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1269088
URL: http://3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com/USA/Setup.exe
URL Status:Offline
Host: 3b39e40c-13d6-4a1f-a716-d0986744cc54.s3.ap-south-1.amazonaws.com
Date added:2021-05-22 07:02:14 UTC
Last online:2021-05-29 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-05-22 07:03:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:6 days, 20 hours, 39 minutes Bad (down since 2021-05-29 03:42:18 UTC)
Tags:ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-25n/aexe da9abc7cc54d7aeb2fd176f838d807d495615f68b25068abd939c7595ffcbe4an/a 
2021-05-24n/aexe 1e88a169aec46c8f54680f4d4d7ecec36dc0482ce5b067bbd901f3f8fc5afe2cn/a 
2021-05-24n/aexe a439026408378e73e65afe890e517d9fd78ed55739840cd0eec1e0d83056dd33n/a 
2021-05-22n/aexe 59cc6a413c0ff4adeb9f693c418301685d7d3310939bc3ec19750da9a33a832bVirustotal results 38.57% ArkeiStealer
2021-05-22n/aexe f91c7c2e15b7343d97bc5c3961f43ebd659440102a4a9c3359d7a9e6e0aef9d3Virustotal results 40.00%ArkeiStealer