URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.133/WW/file8.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1381569
URL: http://136.144.41.133/WW/file8.exe
URL Status:Offline
Host: 136.144.41.133
Date added:2021-06-20 06:28:03 UTC
Last online:2021-06-30 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-20 06:29:02 UTC to abuse{at}serverion[dot]com)
Takedown time:10 days, 2 hours, 31 minutes Bad (down since 2021-06-30 09:00:33 UTC)
Tags:32 ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-29n/aexe c7b160a09b5c65d67c34c98404652fb7909dc990fbd40c06a89629a9ce65397en/a RedLineStealer
2021-06-28n/aexe 42e4233468438e37df608db8eb2590e59bb53f496e3315eddd912adeebccbc51Virustotal results 33.90%RedLineStealer
2021-06-27n/aexe d558cc04e58bc38d16eef52232c921c59fdb916b33dd412aac99eec3076fc14an/a ArkeiStealer
2021-06-26n/aexe 9d4ae0f85b422c0a89e523338d6d130753dd66623674d65dac4c297be9be93edVirustotal results 39.71%ArkeiStealer
2021-06-25n/aexe e358fd349ec54deaa1a4926892dd9e1e261777976f78f87627e54e3cbff06019n/a RedLineStealer
2021-06-25n/aexe f320634bc3b9bb874f96200d760a2aa93060e611a6bde0020056543339ab351cVirustotal results 35.71% RedLineStealer
2021-06-24n/aexe 3d705abdba4062196f5549f2a653462552ddc97ffebdcd257818572ffed3dfdeVirustotal results 40.00% RedLineStealer
2021-06-21n/aexe cab3e6e2c9a366a7e2276c6f224c8788d3ae7c03d217ac01bd43b1d7cc1b3758Virustotal results 47.14%ArkeiStealer
2021-06-20n/aexe d99af28c97f63d10334623749b1e0daf3c05387d827b02c83c19c6400114bc06n/aArkeiStealer
2021-06-20n/aexe b0bf944eb3f2f6706a87e98b89a862ac20501beda28e8805116190f51bb56133Virustotal results 60.87%ArkeiStealer