URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.133/US/relvo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1372392
URL: http://136.144.41.133/US/relvo.exe
URL Status:Offline
Host: 136.144.41.133
Date added:2021-06-17 09:40:06 UTC
Last online:2021-06-24 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-17 09:41:03 UTC to abuse{at}serverion[dot]com)
Takedown time:6 days, 23 hours, 27 minutes Bad (down since 2021-06-24 09:08:28 UTC)
Tags:32 ArkeiStealer link exe FickerStealer link RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-23n/aexe 2ce292291e0e0500b132b502c6ad7fc5e50317f73127c799b3b2bfa3dd387c92n/aFickerStealer
2021-06-23n/aexe f0d154ce286108dd1484845cabd99348f38b99b8f7dd64d8bfa9547a82a8bebfn/aFickerStealer
2021-06-22n/aexe 54476bdb2f90524ca3fe8997505b1e619f37ff532048b6aec6eded091736296an/a ArkeiStealer
2021-06-21n/aexe 1caf2367b85edbe5a5330d1edee51ac80aaacb99529d98a22cf847381db56edfn/aArkeiStealer
2021-06-21n/aexe 4b5e1c17abc2daf1f7be119d981066cbd035c3266da1c74c5560daa5e6fc21ban/a 
2021-06-19n/aexe 3d528b742ada6b08740dd5413b53471fadd61ca065332bd768904603bd640fa6n/aRaccoonStealer
2021-06-19n/aexe 261a6b5bd61c119a30c55227f035b3fa9e4d34fdbdcf97663cbcf771fc62a25fn/aArkeiStealer
2021-06-18n/aexe 3bbc9dc239950316f60ce159afff3e7d7d1ea57c0feb1288a699da981662b9d5n/aRaccoonStealer
2021-06-17n/aexe dd1dea95bf17e3f135d2740e87d8b9f08ccf347e4ff832b9e747f775017ff346Virustotal results 33.33%RaccoonStealer