URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.241.136/files/file6.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1318737
URL: http://212.192.241.136/files/file6.exe
URL Status:Offline
Host: 212.192.241.136
Date added:2021-06-03 06:10:03 UTC
Last online:2021-06-08 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-03 06:11:19 UTC to abuse{at}des[dot]capital)
Takedown time:5 days, 1 hours, 16 minutes Bad (down since 2021-06-08 07:28:13 UTC)
Tags:ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-07n/aexe 4dfa827a77bbae8f9546fe3a4a74bc522bde248b7f168e3cd5ec40afd5468467n/a RedLineStealer
2021-06-06n/aexe 4c07999c8376f23a0b44ddb98b4dc2a05e7decdd959b0468fb038adcaf932198Virustotal results 42.86% RedLineStealer
2021-06-04n/aexe 6dfc5e15040bfa96f6d5042287a4433c3cad197d4528f885dfafb456cf147a1bn/aArkeiStealer
2021-06-04n/aexe d5580203a83b0cfdf635b13c040160764b453f3fbb25303521bfaab6955745d3n/a ArkeiStealer
2021-06-03n/aexe 7c5f0cda2c6d39ef3ac2d2a4075462243e17ff265e53f0facf4206e5a4c4b92cVirustotal results 19.12% ArkeiStealer
2021-06-03n/aexe f4b0480abfb5b1dd1f9e13a0d433659f4706cb3f8805b2f9705062ea79904db8Virustotal results 51.43% RedLineStealer