URLhaus Database

You are currently viewing the URLhaus database entry for http://147.124.212.189/files/mar-signature_request.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1764572
URL: http://147.124.212.189/files/mar-signature_request.exe
URL Status:Offline
Host: 147.124.212.189
Date added:2021-11-08 15:07:05 UTC
Last online:2021-11-12 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2021-11-08 15:08:12 UTC to abuse{at}spinservers[dot]com)
Takedown time:4 days, 7 hours, 57 minutes Bad (down since 2021-11-12 23:05:39 UTC)
Tags:ArkeiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-11n/aexe 6a86335380f777a4f1979a4aefd529777fa51f4478a8bac2cc3b9e5759566445Virustotal results 25.76%ArkeiStealer
2021-11-09n/aexe 2d595ac494ab682a6e0b5fdfe53a7ce865328f6df521ed3e8e9ee2486d81a3aan/a 
2021-11-08n/aexe b0603a89ffbcfd44a535b90ebd1b9303cb896dc83245fa805c7dff8953b1ea2fn/aArkeiStealer