URLhaus Database

You are currently viewing the URLhaus database entry for http://206.189.3.174/Vids.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1595411
URL: http://206.189.3.174/Vids.exe
URL Status:Offline
Host: 206.189.3.174
Date added:2021-09-05 23:21:03 UTC
Last online:2022-03-15 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-05 23:22:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:6 months, 10 days, 22 hours, 13 minutes Bad (down since 2022-03-15 21:35:25 UTC)
Tags:32 ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-13n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2021-09-06n/aexe cd9d965902a94d210c03d020d9d239be113bd1ce016dfa8b0fa408b6eb8c5be0Virustotal results 43.48% ArkeiStealer
2021-09-06n/aexe aef892cd55bd732e56733bb0601cf033251a88d7986199c9b9ae8cb006602a37Virustotal results 41.18% ArkeiStealer
2021-09-06n/aexe 295d3a815f7917fd944d28e08e46d1a45c7ac9a5ffcb9fd2a697cc4d84352d56Virustotal results 41.79% ArkeiStealer
2021-09-06n/aexe 353804086c15fe84601bd729f97643161e22dffb309f5eb98733bdac2d141f2aVirustotal results 36.36%ArkeiStealer
2021-09-06n/aexe afaa0f7e859fdd8e68f00d6616e8e0dddf8c33331b47aa0987fc60118810574bVirustotal results 31.34%ArkeiStealer
2021-09-05n/aexe 0e5895d15b6e3ca830858d87198da7750bc001d4bce5294936a4b8cbfd907109Virustotal results 34.33%ArkeiStealer