URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.201/WW/file10.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1421030
URL: http://136.144.41.201/WW/file10.exe
URL Status:Offline
Host: 136.144.41.201
Date added:2021-07-02 21:32:03 UTC
Last online:2021-07-08 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-02 21:33:02 UTC to abuse{at}serverion[dot]com)
Takedown time:5 days, 7 hours, 8 minutes Bad (down since 2021-07-08 04:41:59 UTC)
Tags:32 dcrat exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-07n/aexe db4dd0ad6b5d4922fc1375f1c2e2c83e8e2316dbf72963dca142a53cd7b06430n/a RedLineStealer
2021-07-06n/aexe 2513063162e69e59ce679b97d76ed263a0cb9eb503033e59b921f2a2c01106edn/a RedLineStealer
2021-07-06n/aexe 219c4434e7581ede558f4a082a37bf29fea45c304e750e347cef20ee3a4d1243Virustotal results 35.29% RedLineStealer
2021-07-05n/aexe c144b9c8ba25c23f058ddcae2adb58f474c1e7c660c91d0417d1ec57a8029e8cVirustotal results 42.03%
2021-07-04n/aexe a9ee9e1fb2ff7c982928f635dcef8952a1b289116f517d7b99628707b69f06b3Virustotal results 27.54% RedLineStealer
2021-07-03n/aexe 8ba82e727422e153c3d1be5adceb1f04138234afee47a7f97dc4c93c5b034106n/a RedLineStealer
2021-07-02n/aexe 371721d174fb4da7167a64d2469b8b9c4f9c4da386a7ef3a2d9da94b771755c7Virustotal results 27.54%DCRat