URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/WW/file8.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1642822
URL: http://2.56.59.42/WW/file8.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-09-24 20:42:04 UTC
Last online:2021-10-06 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-24 20:43:03 UTC to abuse{at}serverion[dot]com)
Takedown time:11 days, 10 hours, 8 minutes Bad (down since 2021-10-06 06:51:45 UTC)
Tags:32 ArkeiStealer link exe RaccoonStealer link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-06n/aexe 1b15728dff2f837bf0a6e7da01a2ba98fa4b1cb2b2437d5d1f9f730eaf54a49bVirustotal results 46.38%ArkeiStealer
2021-10-02n/aexe 17ae329b1ffd8bd8f503fe74eb8bf59982b5fa3d58d7b67545e2a64d316a4c68n/aRedLineStealer
2021-09-30n/aexe 042dcdb128cad476807aa96e2e16c6e32e40ae4b33283227b0bcfaa2ea95cd30n/aRaccoonStealer
2021-09-28n/aexe 4900ff939aa51f69a0e5ff59adcb65655645af6c8d51dc0a7ea7206d5551a237Virustotal results 44.78%RedLineStealer
2021-09-27n/aexe 7635050a23f330196ef94aad945476d5b7079fe1e01c90f395d6cab05762c7d3n/aRedLineStealer
2021-09-27n/aexe 98f84b15da1ec1d5cbff6cfcc51465a609fed327159eee4f7874dbffa2054435n/a RedLineStealer
2021-09-27n/aexe b5cbda330690bd2371eb91aba1b7d48b47dc11e1939af678945fb58a0059052dn/a RedLineStealer
2021-09-26n/aexe 96c492f131ad78dd56a5f3f9d23d7481e9e3c7832073fe93e9ebe25d6a0b9e7cVirustotal results 41.18% RedLineStealer
2021-09-24n/aexe 7a5a953b328eddffbd69d55bc2d6626c353bcef9a9a9f4efec49cdaa7ac601acVirustotal results 35.00%ArkeiStealer