URLhaus Database

You are currently viewing the URLhaus database entry for http://91.243.44.130/stlr/maps.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1947948
URL: http://91.243.44.130/stlr/maps.exe
URL Status:Offline
Host: 91.243.44.130
Date added:2022-01-04 06:46:06 UTC
Last online:2022-01-07 23:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-04 08:42:33 UTC to abuse{at}grizlnet[dot]com,abuse{at}vamu[dot]ru)
Takedown time:3 days, 16 hours, 26 minutes Bad (down since 2022-01-07 23:14:34 UTC)
Tags:ArkeiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-07n/aexe b7157958f990bba7043746bf9d34a4da7a312c219883016cc9ae931c49fd3d4an/aArkeiStealer
2022-01-06n/aexe 8754fc94bb3b8faf216ba5698be5f210dbd66869fc295fcf362cd691c483be18Virustotal results 33.33%ArkeiStealer
2022-01-06n/aexe b912d450e6f45f40fcc8d4d6a056206667f56b4a61100e2c3f43589c50bd6e6eVirustotal results 31.88%ArkeiStealer
2022-01-04n/aexe e03315664302a299233cf88fbe8792f36bf5c76c16a936270866e0ade1b72382n/aArkeiStealer
2022-01-04n/aexe b8b942c702f57d78578f42abaa04906a42bb09c8c88731e71b9509a5509aae2fn/a ArkeiStealer
2022-01-04n/aexe 9cae87b1118c6142f014a4a22be3a4489f40465a7de9e5cfa9aa019817e2dea4Virustotal results 26.47%ArkeiStealer