URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.11.8/WW/file2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1478752
URL: http://37.0.11.8/WW/file2.exe
URL Status:Offline
Host: 37.0.11.8
Date added:2021-07-24 18:18:03 UTC
Last online:2021-08-14 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-24 18:19:03 UTC to abuse{at}serverion[dot]com)
Takedown time:20 days, 11 hours, 3 minutes Bad (down since 2021-08-14 05:22:12 UTC)
Tags:32 ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-13n/aexe 558a7926f89fff18563d27fbd71429af8c9f5d0f7b3cb3702cc102d08645ca59n/a RedLineStealer
2021-08-13n/aexe 1d7d718be5b978fedd1124fa44831ba54af5bda0507f6eee05a0a8c8d9badda1n/aRedLineStealer
2021-08-12n/aexe 110bfbd9eb6791efc6612b370f0e54e7d8d5a631b9fa4b55db13b062a47a2e0cVirustotal results 44.78% RedLineStealer
2021-08-11n/aexe b0ce8db8d3a8a08c71622ffa7a369a8f69cd649f905ef29fcfc7171a2de3e134Virustotal results 43.48% RedLineStealer
2021-08-11n/aexe a2ac6fd6156acf555c5eabc6a1bd33d03f6d569ae5a9485c6c6619d6292fde01Virustotal results 25.71%ArkeiStealer
2021-08-10n/aexe f028c63f28b24009fcb36f8ddb4e637c8c19c43a6a49f93875c097b9291cc136Virustotal results 70.00% RedLineStealer
2021-08-08n/aexe 9449aae1c3258cd4b7290aacf6e00a3884f0ab1da99194082416815d61033dfeVirustotal results 60.00% RedLineStealer
2021-08-04n/aexe ddb3ea989aeba953c5e62ab710371b75bd78eaee4dff5facf08ef65cd07e9bdfn/aRedLineStealer
2021-08-04n/aexe 26285efdd77665c7dd35aa0450f77214644ebb80fb284e071e67f728881c8983n/aArkeiStealer
2021-08-03n/aexe 9bfdd2efd383301a4a8f714dced13877eb0dfc894994b6d78a31a432ece416cfn/aRedLineStealer
2021-08-03n/aexe bb9a6242991d0d9bf29011e503cb679537dda42fab5451869ce866b3dada19can/aArkeiStealer
2021-08-03n/aexe 0cdbdd0309645bd9e13aa592be19ab33ca6812037504aadab7558968d8a62206n/a ArkeiStealer
2021-08-02n/aexe 342d473a1823700bb85ca5d7634c277eec041f4e0187d6bb07a7ee598488d520n/a RedLineStealer
2021-08-02n/aexe e61790896841491a5e0e96cd8a7e65c87cbc24a487605d38b4f2633b87d2dfe5Virustotal results 44.93% RedLineStealer
2021-08-01n/aexe 68e03c80c66e68fb070755732ef107f3e41cfcca10b143f062de004ab9baa7d1Virustotal results 52.31% RedLineStealer
2021-07-30n/aexe 6a9a058d16d72684d3acf16c16ca5454a9de9b1204b91eece3669de2fcd06187n/aRedLineStealer
2021-07-30n/aexe c7ec5e55d90f05cda97e8de87ce1026dc926e7e7aaeb4d2f5051cadd1043bc79n/aRedLineStealer
2021-07-30n/aexe 775b8d456b6e65aca697f97e6326441368cee795a1b96c6ca7a4dbba1719154en/a RedLineStealer
2021-07-29n/aexe 0fb7d001e28f45c69936e416afbb84866b1d24d3c53a6f0cd3452a2272baa313n/aRedLineStealer
2021-07-27n/aexe f3d5ae4cb68b6a2b5ac818fbb3e7fe78bf49ce36e768f0f73d61f5870d2f7d52Virustotal results 27.27%RedLineStealer
2021-07-25n/aexe f46f98657c2e7c431156f15113dfd20eda7861f6f360ac12b172dee382c73cb7n/aArkeiStealer
2021-07-25n/aexe 877361729f6caeec07146bbacb86e5ea7597085b946e5f81f79db0e0eba72035n/aArkeiStealer
2021-07-24n/aexe 2636faa0941a7fd9a889aeb2e4b94fe95f538a588642750ac87d635fd68b5537n/aArkeiStealer
2021-07-24n/aexe ca77fa6ea006bb61812c11571551a058721ae6e829bf38afd8ba1c17d1d65e36Virustotal results 17.39%ArkeiStealer