URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.201/WW/file1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1424949
URL: http://136.144.41.201/WW/file1.exe
URL Status:Offline
Host: 136.144.41.201
Date added:2021-07-04 07:10:04 UTC
Last online:2021-07-24 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-04 07:11:03 UTC to abuse{at}serverion[dot]com)
Takedown time:19 days, 17 hours, 48 minutes Bad (down since 2021-07-24 00:59:24 UTC)
Tags:ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-22n/aexe cab81fbf16ca9e47efd63a5ade336d73dcfa12d2efd4a12ec2692a8aa0df9314n/aRedLineStealer
2021-07-22n/aexe ce6008f9953e597c3c406a60f3efe1157c4c8eccd5d9d8070a621dfe2f12204bVirustotal results 17.39%ArkeiStealer
2021-07-21n/aexe 61038a3b015db3ea6123fb1744dfef09c105fb41b1943ad8cd5d8107ba27f24eVirustotal results 62.86% RedLineStealer
2021-07-18n/aexe 2cbe0812081f1c8676e8fb96d9e4e08e6ac092c38982586030bd7302ed2b9a2dn/aRedLineStealer
2021-07-15n/aexe 3659c9a886b9b3e08e4f5eeb08d40bf9f1729e0869114cd8d390d28e6120e3c4n/aRedLineStealer
2021-07-13n/aexe c60fb11bf7e8e6be4c2574c6f129150260a5ea16af32faed72241acd5e03acc4n/aRedLineStealer
2021-07-10n/aexe f3416afee6b84257031de7bc3a3135556308b5749fcafb14639a12e3625c450fVirustotal results 47.14% RedLineStealer
2021-07-07n/aexe 9dc2aee4b65b09658a4412e9cd10aaf655faeb9b5500241455c0183150581e1en/aArkeiStealer
2021-07-04n/aexe a6f665f65622f234094846135c95813928b5aa66673ec484478f58f8d8416841n/a RedLineStealer
2021-07-04n/aexe 26b9f3438e837381a4a345bbf922ded0bdfdc0f5471dcae1ce1322b745c8bcc5n/a RedLineStealer
2021-07-04n/aexe f3f540378e07c4686e0d910a8e98285469e360415844f97f0bbbce295c2142b6Virustotal results 64.29%RedLineStealer