URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.241.136/files/file4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1288378
URL: http://212.192.241.136/files/file4.exe
URL Status:Offline
Host: 212.192.241.136
Date added:2021-05-26 21:28:04 UTC
Last online:2021-06-07 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-05-26 21:29:02 UTC to abuse{at}des[dot]capital)
Takedown time:11 days, 18 hours, 4 minutes Bad (down since 2021-06-07 15:33:15 UTC)
Tags:ArkeiStealer link exe QuasarRAT link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-07n/aexe f543bca03c8aab5bdf2f069ddaabda9f339db5f686a4b4275d7db32183c2655cn/aArkeiStealer
2021-06-06n/aexe 3acdafc3dc9b1306c0422042253c118d0a0d0601fc2af40a3bbc598599d70f03n/aRedLineStealer
2021-06-06n/aexe 1ebe3d0893fdb764e85ba28bbd9f2cc49093a56b6f66cdf4c987e21fd0a4208dn/aRedLineStealer
2021-06-05n/aexe fe1f6de2afb6a467285081c533f7cb8a01267ad9abd9611ee8692664d258ebe0Virustotal results 20.59% RedLineStealer
2021-06-04n/aexe d63034839551a1355c462f0f912af9f3f303460f22e1398b73688731f010a5ddn/a RedLineStealer
2021-06-04n/aexe c7d0d8513552fd13ecb15e4fd518549aa71498af923b024e721a527b5d7682b3n/aArkeiStealer
2021-06-03n/aexe f3111a72a43115727e0224015777dbde5f4dbf285fff1b7b28f5444fa19c5310n/aArkeiStealer
2021-06-03n/aexe 9619ec4c9365cd56792946de399763629e69dcd912484a968167cf4dba9668adVirustotal results 50.00% RedLineStealer
2021-05-31n/aexe 5a06f37e10c68b0cc5a7649e161625303f6e8d6a3fe1624cbb712e7a710668c2n/aQuasarRAT
2021-05-31n/aexe d1504cb2f00c4f69ff6a019016a0baf990e135c558e48c4beb8f1a40574d7c14n/a RedLineStealer
2021-05-31n/aexe 55342589e3d128aa53314e613bab6608de3c0f69ed1dae8b5acf5ba694c54c7cVirustotal results 17.39%RedLineStealer
2021-05-28n/aexe 4a696d03683e7cbf62d8b8644ac5b8fc5df9fa41da72001ba6b0f437154202f7n/a RedLineStealer
2021-05-26n/aexe 82bb1b070ea558aaaa245858b9b89761c8b41a176a45ce61b91044c57e44b1d4Virustotal results 38.57% RedLineStealer