URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.11.8/WW/file3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1478795
URL: http://37.0.11.8/WW/file3.exe
URL Status:Offline
Host: 37.0.11.8
Date added:2021-07-24 18:49:03 UTC
Last online:2021-08-13 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-24 18:50:03 UTC to abuse{at}serverion[dot]com)
Takedown time:19 days, 9 hours, 28 minutes Bad (down since 2021-08-13 04:18:49 UTC)
Tags:32 ArkeiStealer link exe LimeRAT RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-12n/aexe 9af2474823d8274925ccbc39726f4766c675c3e996dedfbbb6a4b07d86af6fe7n/a RedLineStealer
2021-08-12n/aexe 40480036363a57a125f0ba8d78005327b8e3f7d496d486961e75bf67089034bcn/aArkeiStealer
2021-08-11n/aexe 5920f9887ebfba9838fbbfda9530dd2923726a6317e6edbfde85e61bd053fb1dn/aRedLineStealer
2021-08-11n/aexe 63dfcc5b81dbbca65625748e57496c8935e46a35b3c89487c75269812764bb9an/a RedLineStealer
2021-08-09n/aexe 7cde61d40a49c50829fb9219fa8556768d18b9ec7ac362b04880ed7e52528073n/aRedLineStealer
2021-08-08n/aexe 3114d9a19def58cc62a9b5dbe78360e64772b46e1815c974f318cafb99eedc98Virustotal results 17.39%ArkeiStealer
2021-08-07n/aexe 8e4a5d38a79f1f13297db22e68805711767767e159e6f8eec469b842a38caea2Virustotal results 57.14% RedLineStealer
2021-08-05n/aexe dc2dcd2c5123a6f716272b92b427d6889566ee08e7b46bfb4878c028964260eeVirustotal results 60.00% RedLineStealer
2021-08-04n/aexe b3b10dd428f6843a7fe7a3b32aeb530910da6bbe3bf45b6b1688b3701ace2200n/aRedLineStealer
2021-08-04n/aexe af38d6c48da79188980837cf60c19ab2479f20f600780cb33954a2bdf5031db2Virustotal results 50.00% RedLineStealer
2021-08-01n/aexe a25ec3a67a8a2d7a4baff4f55b6b4e9ca4ff31bcb866d45eff42893c14d766cfn/a RedLineStealer
2021-07-31n/aexe 0344c20e70f91bc71b10fb60f5043bc07f238d1439b277fec325b3cc10c19668n/aRedLineStealer
2021-07-31n/aexe b55f8591fbd2f897def00aa5fbf50b23d080839a24303227024d63e1186961a7Virustotal results 49.28% RedLineStealer
2021-07-30n/aexe 45d8a91be1d071837969fc7801a224b06e918bdc813e7ec14348abf8d0810312Virustotal results 30.00% RedLineStealer
2021-07-28n/aexe afd7b91be42e614fa8f3488f8cf2024b1a5b364c4b66c514fa86940b06c93515Virustotal results 44.12%LimeRAT
2021-07-24n/aexe e1130b856161680a39ebf5d759bd25663b598e69b6ef68721933958ac644a496Virustotal results 50.00%RedLineStealer
2021-07-24n/aexe 35db5b59f62e3dc3187c543b4e5cd623f5c3905f89ae046877c2fa5b69cf5e39Virustotal results 65.71%RedLineStealer