URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.133/WW/file2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1357954
URL: http://136.144.41.133/WW/file2.exe
URL Status:Offline
Host: 136.144.41.133
Date added:2021-06-12 16:02:04 UTC
Last online:2021-06-30 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-12 16:03:03 UTC to abuse{at}serverion[dot]com)
Takedown time:17 days, 16 hours, 54 minutes Bad (down since 2021-06-30 08:57:41 UTC)
Tags:32 ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-30n/aexe 9f2d892a4f124d1b693d8ceafc6ebe8741484109f68d82ec49ac2c9d781483a7n/aArkeiStealer
2021-06-28n/aexe f1e6ef95e8fb839899a496e6ce304bca0be925f2473d0f9ecf250ee6ba330233n/aArkeiStealer
2021-06-27n/aexe 0f48b95257e34ab07069a73b1eeb49d2c495cc37f4f1477e0a112f1424b25ebfn/aArkeiStealer
2021-06-26n/aexe e8104ac6fcd1052611d0de47d66087dccd5e2a0332b26d90d2bd9a68c903330bn/aArkeiStealer
2021-06-25n/aexe 8f1ec2b723ec84f616415cf2470ee78ccaf8ea429f3d1f25b82709502366028bVirustotal results 38.24%ArkeiStealer
2021-06-24n/aexe 71407dd4cf7787d2529b435a8e24e0899b0b2e5ab0482abcd507ecd862358923n/aArkeiStealer
2021-06-24n/aexe ecb91f6f4a1563acf0b93302e3186ff569ba6cc9d504b9729a1d90111cf95605n/aArkeiStealer
2021-06-23n/aexe f1d5dc6a5034e923700d9a89f322804ee7e282e3fff83b09956001c30499878en/aArkeiStealer
2021-06-22n/aexe 8be9cec521fca3b82e924f94f7d13b253a9259c0ead8cabc4a71cd26d2ca8b7bn/aArkeiStealer
2021-06-22n/aexe cebeadbb9831d323543239700725457c942d4a08515f4a52152ee0310699b296Virustotal results 27.54% ArkeiStealer
2021-06-22n/aexe f8142112b141de8d1672bc3f0d2eaac2062d4917b462fa939767e14891ee2048Virustotal results 47.14%ArkeiStealer
2021-06-21n/aexe 50762d9a72db84ac08da5b2b4ab3e62b3d581697c087f6c8991ae83c951f6f96n/a RedLineStealer
2021-06-20n/aexe b55dd061a60905c3a2208917883d326b08a3a7d1f8fdb94f78e6675375fc8219Virustotal results 10.14%ArkeiStealer
2021-06-15n/aexe 0f46d6e5d68bc545730ec2ac05d6ecde721437e0fb4dad8be97ddcdced1b50e9n/aRedLineStealer
2021-06-13n/aexe 5707e4c1b0cd547a96128d50b8ba0487323681cc3edd97d878b2d399e665c6bcn/a RedLineStealer
2021-06-12n/aexe fde7164e40a4441b073b4258a7d13fee88fc2d9f6cb5d7d42cfcec774e6d6cc5n/aArkeiStealer
2021-06-12n/aexe 5c4ca53b4a841b95c0ee07f07599236e53f17998c2b0ecd3c68ffddbf71d29b9Virustotal results 55.07%RedLineStealer