URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.241.136/files/eu/file31.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1320964
URL: http://212.192.241.136/files/eu/file31.exe
URL Status:Offline
Host: 212.192.241.136
Date added:2021-06-03 18:42:05 UTC
Last online:2021-06-08 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-03 18:43:06 UTC to abuse{at}des[dot]capital)
Takedown time:4 days, 15 hours, 29 minutes Bad (down since 2021-06-08 10:12:22 UTC)
Tags:ArkeiStealer link exe opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-06n/aexe 0140e6a13431a2f6e9157b7d602fd38f4f1603aee2c07219ff8af2fa2f63fce9n/aArkeiStealer
2021-06-05n/aexe ce3b74ec67f89bcfc4cbf5c2fe27dd716f3edf01107c40533d1e53234d75812en/a ArkeiStealer
2021-06-05n/aexe c391ea2f8b72e2810362cd512a640220f20fb149bdd85eaef408c25471f74b92Virustotal results 28.57%ArkeiStealer
2021-06-03n/aexe 9efbb419c2aff8a828887c19b9f7d75b9432ac2942737f1a55a8359d8dbf73d9n/a RedLineStealer