URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.201/WW/file6.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1453954
URL: http://136.144.41.201/WW/file6.exe
URL Status:Offline
Host: 136.144.41.201
Date added:2021-07-14 14:21:04 UTC
Last online:2021-07-22 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-14 15:24:27 UTC to abuse{at}serverion[dot]com)
Takedown time:8 days, 2 hours, 43 minutes Bad (down since 2021-07-22 18:07:42 UTC)
Tags:ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-22n/aexe 966587a4421c9d7cab7b5defc79a47e7c319f0bd4166678d3a0425b85ca540bbn/aRedLineStealer
2021-07-21n/aexe b61afe14307f31673f7ca5970d1bc8226dc21ef34a3f71a549025bf5babb3e86n/aRedLineStealer
2021-07-21n/aexe a66228e6a0b619a07070c311713d3630b53a89a3e7fdd4b871859e001e693329Virustotal results 47.14%ArkeiStealer
2021-07-19n/aexe 3ae097ee6a269763737b21e1cdfb7277b049998b4396b52f752b1cc2c9cb2da2n/aRedLineStealer
2021-07-14n/aexe 94e450e112c9ce71d4680efba06104c70bc7646efe019019e08318f291ff657aVirustotal results 41.43% RedLineStealer