URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.241.136/files/file7.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1318738
URL: http://212.192.241.136/files/file7.exe
URL Status:Offline
Host: 212.192.241.136
Date added:2021-06-03 06:10:04 UTC
Last online:2021-06-08 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-03 06:11:19 UTC to abuse{at}des[dot]capital)
Takedown time:5 days, 1 hours, 33 minutes Bad (down since 2021-06-08 07:45:11 UTC)
Tags:ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-08n/aexe 323673b5ac7a95ea53f2a38c8c7d51206caf1fe95dc8c4f17c4e629154b2f607Virustotal results 54.29% RedLineStealer
2021-06-05n/aexe 81fe489ee1e11d9243c24fd26f5902af91e3ab710e82aee11e3f8706881cb579Virustotal results 29.41% RedLineStealer
2021-06-04n/aexe c391ea2f8b72e2810362cd512a640220f20fb149bdd85eaef408c25471f74b92n/aArkeiStealer
2021-06-04n/aexe ab1a97eb26ac1c7e2903b32f7f0681c57f35fa28c6cbe1f9f30eb347e437633aVirustotal results 36.23% RedLineStealer
2021-06-03n/aexe a46f22fecc59d99c6abbf24076db9dab47f5a3e4ef5bfec8bb37b0d164a8d1f5Virustotal results 30.00%RedLineStealer