URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.207.48/obi/can.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1447745
URL: http://198.23.207.48/obi/can.exe
URL Status:Offline
Host: 198.23.207.48
Date added:2021-07-12 13:55:05 UTC
Last online:2021-07-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-12 13:56:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:10 days, 20 hours, 33 minutes Bad (down since 2021-07-23 10:29:13 UTC)
Tags:exe opendir RedLineStealer link StormKitty

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-20n/aexe 5e0f712886c0970f0ce44e8c0c658c9e2e40a81cb6e6fa065b52a60b4f080952Virustotal results 32.86%StormKitty
2021-07-19n/aexe 3f46e10e5fe376b995e2947d1be21955aa8341f39d80cca737109fcf2cf2bf3bVirustotal results 14.71%StormKitty
2021-07-19n/aexe 8a7a54c2c7952b89a9bd9898ee42e52da9aeb17e41a878f2a5236401f3e14efan/aStormKitty
2021-07-19n/aexe 413cdd0ae3d9ba60b132796a63dad08bea31d309157f5497380ad72cb3b0ae27n/aRedLineStealer
2021-07-14n/aexe 1237dcbb21554e1a3f7ba70785c7f449158a8063633fcbd1e96c4a34098ace9fn/a StormKitty
2021-07-14n/aexe 463ace81e13b8db2ec0d6ee4182e27a7a91c9c65555006ad064cd1e27e92a46cn/aStormKitty
2021-07-14n/aexe 8130e7cb38e727c9f90c9ec404685cffdff6c731d780ba7220af582cadadb30bn/aStormKitty
2021-07-13n/aexe 84c1024292142c4d234701e830aedcbd865311693f0d8ac75596deee268c7db5n/aStormKitty
2021-07-13n/aexe 3504fe4b0e2d093c366cffa43ceb37026d7a5f8e35498aa7945556c77ecce731Virustotal results 26.47%StormKitty
2021-07-12n/aexe f66e5f355ec3477cc1be168b9fec2f85d2c58106460d988dd96855f8c78b3fe8Virustotal results 36.23%StormKitty