URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.201/WW/file3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1453956
URL: http://136.144.41.201/WW/file3.exe
URL Status:Offline
Host: 136.144.41.201
Date added:2021-07-14 14:21:04 UTC
Last online:2021-07-24 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-14 15:24:27 UTC to abuse{at}serverion[dot]com)
Takedown time:9 days, 18 hours, 10 minutes Bad (down since 2021-07-24 09:34:33 UTC)
Tags:Amadey ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-23n/aexe 35db5b59f62e3dc3187c543b4e5cd623f5c3905f89ae046877c2fa5b69cf5e39n/aRedLineStealer
2021-07-22n/aexe 02e9bbebcc372e37d18f0dfed9c2dc5e50a23b7305aa3527accedba48bbd8432n/aRedLineStealer
2021-07-21n/aexe 309aa6af647b1267fef90257e69cfe6be01ed03d3bbcc512dba951bbf4056916Virustotal results 40.30%RedLineStealer
2021-07-19n/aexe 0afeecacdddfdd9a9609abba82f70ccfd06d668536b09220c34e807e5f3b8557n/a RedLineStealer
2021-07-18n/aexe b26d99afb381ebd0cc0547b8523498d1ab2de16a7bb668db985d8b605fa96449n/a RedLineStealer
2021-07-18n/aexe 42054b960727fbd72bde57e8903881e4239e9500f1160ca298e10a1b438698a8Virustotal results 23.19%Amadey
2021-07-16n/aexe 1f994101b6ce015c09ee67933c1c7e7187cd0ec033bb0525e85e8a5a49892f43n/aRedLineStealer
2021-07-16n/aexe f225bbf82fff267fddb8e3dc88a5f707af1a238e5ed5408282fd176af6f5b8a5Virustotal results 39.13%RedLineStealer
2021-07-14n/aexe 926d7ec0b89588104045819ed00a8a950999d3b981c2260c69577b4877bb2594n/aArkeiStealer