URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.59.42/EU/asdfasdfasdfasdfasdfasdfasdfasdfasdf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1666411
URL: http://2.56.59.42/EU/asdfasdfasdfasdfasdfasdfasdfasdfasdf.exe
URL Status:Offline
Host: 2.56.59.42
Date added:2021-10-11 10:01:04 UTC
Last online:2021-10-17 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: ffforward
Abuse complaint sent (?): Yes (2021-10-11 10:02:05 UTC to abuse{at}serverion[dot]com)
Takedown time:6 days, 10 hours, 27 minutes Bad (down since 2021-10-17 20:29:38 UTC)
Tags:ArkeiStealer link exe Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-13n/aexe 98ee19dbbe959081f2d95b7f56af58fcb7ecdc5b85bb9ee13775376b9bad1ccfn/aArkeiStealer
2021-10-12n/aexe 575d3a4edbf03fc3bead2e44d9f8a65047ff8f7e90d9130eca7a6825bc92fb56n/aArkeiStealer
2021-10-11n/aexe e5122b8f9175869275bb1dbbafcf3e1a199a257b4dcc5d36de6d1b5f610d5195n/a ArkeiStealer
2021-10-11n/aexe cdd1ac2ccf205bcc0e8fecb0b117b809fcade0fcc0eba5f6b85a5dfc88443344n/aArkeiStealer
2021-10-11n/aexe d6e566d286fae051384f3789f262e4ba76b8e92a4937285bd94f9d031cf323b9Virustotal results 13.43%ArkeiStealer