URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1642816
URL: http://2.56.59.42/WW/file3.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-24 20:37:03 UTC
Last online:2021-11-24 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-24 20:38:02 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 0 days, 20 hours, 46 minutes Bad (down since 2021-11-24 17:24:47 UTC)
Tags:32 ArkeiStealer link AveMariaRAT link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-24n/aexe 1e1f6506827ffebe66c5d67ed0596b6c9960260062fbb430a94994d52e83afd3n/aRedLineStealer
2021-11-24n/aexe e0696e4a0c55f9492349f1add5c76ea4b341cba547cb2d105d4096471990affcn/a RedLineStealer
2021-11-24n/aexe 3acad0abd816310f3799e2597c8428a89c0f05a6912167517bdeca21bd53011cn/aRedLineStealer
2021-11-24n/aexe 4872655c4b66805a6a8b87f52a9a2132ec60264b023f5076b8283c5659a64cb5n/a 
2021-11-22n/aexe 6093384421389c5a04411fe0807a20ec283ef9bbb248baddce5307cdf38153cbVirustotal results 33.82%RedLineStealer
2021-11-02n/aexe 98b05800dada6d129b26b18ee20664c592d565d51bb7de02e54add7a6cf5a082n/aRedLineStealer
2021-10-28n/aexe 7cfc8c8da463280efb072111a2070ccc1753d807a835513743307eb6426d6cc6n/aAveMariaRAT
2021-10-27n/aexe 283fc46266bd0f72f26690c8193f805efcc13e7e141706b093a386f2e99b5ae9Virustotal results 19.40% 
2021-10-21n/aexe 194eb8fc30f653a5c404a946c8bf6caaa531d35a79259538134437a1f3d681adn/a 
2021-10-20n/aexe 25e716f1573854f3ccb851d2ef5cd139d4087c123c8f9a83b31abafd02ea9d97Virustotal results 32.35% 
2021-10-18n/aexe 62a7d968bb42d9b157da63c1db333c38360da0dc86990cd751c3ec432d932809Virustotal results 40.30% RedLineStealer
2021-10-18n/aexe ba59622733f580592e807c44751503149a54f104b593b097dee0d6cd9e314bccVirustotal results 36.92%RedLineStealer
2021-10-10n/aexe eac035efd7df9d6776a0eb27e2887f566d36d0e50b51044306ffc7862c19036cVirustotal results 17.39% RedLineStealer
2021-10-10n/aexe a511d0605a1ea81db6df8c401b77db2ee5dbdcc8c19849580581a3a7b3a2cd94n/aRedLineStealer
2021-10-03n/aexe 5fbbf8d74c8a2b3f6aabf4a95c1b68d9b5ce182ebd19c1f3c8eed44fdddc72c1Virustotal results 11.59%RedLineStealer
2021-10-02n/aexe fc28ee0a219c9b20301f12ce39585177056a1814f32b3687f90607dd8b7e98ccn/aRedLineStealer
2021-10-02n/aexe 893c359fbf489796d2b12678c3bf882d735c8405828562489c273090c4b15e44n/aRedLineStealer
2021-10-01n/aexe 6c7113b9ae3d2d61d292f42250ecfd6c83db25f0157bb9de2e164b4a98cebe51n/aRedLineStealer
2021-09-30n/aexe 5a937c078e32bcbafa2bc39d1689eead7e714906d13febd08eeb9c05a4e974b0n/aRedLineStealer
2021-09-29n/aexe 3c0de8616a2fef432f4ebb18b449aed6ff28da391aecb990fcda527c5b626d66n/a RedLineStealer
2021-09-28n/aexe e736227edfb8ba484bb37197482804450aa64c0ecd47d36e1e5db24cc3f5ee70n/aRedLineStealer
2021-09-28n/aexe e79ead4156b32abfc058bbc741f6e91ff43b5b903b8bb182586ef7789716b378n/a RedLineStealer
2021-09-27n/aexe 4340bc1e1ddb5d268a010401be96435063de733a2601d158d13f56da9f20df5dn/aArkeiStealer
2021-09-26n/aexe 373c28b9c759d5421a44cd74989e8d625eacdd025d6372c280f848ac8c12ab12n/aRedLineStealer
2021-09-26n/aexe 63a34871b484152dce8b02ce232207e288049a55ff148d0eee8d7571842d40abn/aRedLineStealer
2021-09-26n/aexe fc28af6fd07c69a496b160f59003cb22c07ba256d9d7d7dc56c322d982e79120n/aRedLineStealer
2021-09-26n/aexe e27f862f1e03cd3755a3319c53ab7f0b23720cceedae0d0456090e01e1404d45Virustotal results 27.94% RedLineStealer
2021-09-24n/aexe d85499b6b5d47207653cbd13d93b8e6c28bca67481c6dea3eb3a3bd124b7c1ddVirustotal results 56.72%RedLineStealer