URLhaus Database

You are currently viewing the URLhaus database entry for http://185.112.83.96:20001/build_dl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2037738
URL: http://185.112.83.96:20001/build_dl
URL Status:Offline
Host: 185.112.83.96
Date added:2022-02-08 23:11:04 UTC
Last online:2022-02-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: _FirehaK
Abuse complaint sent (?): Yes (2022-02-08 23:12:16 UTC to abuse{at}abuse-server[dot]su,audit{at}network-support[dot]ru)
Takedown time:19 days, 23 hours, 34 minutes Bad (down since 2022-02-28 22:46:37 UTC)
Tags:ArkeiStealer link botnet exe Hive kraken RedLineStealer link Themida

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-17n/aexe 5d99125b0d97ba0abfcf9916c1a05081c1cc117eb2afaaab39a6f95a60e42ab3n/aRedLineStealer
2022-02-16n/aexe 58484d3924b8c496a925660742b55da793ec4048765edf87c3116e5fb34ebeaen/aArkeiStealer
2022-02-16n/aexe bb5ec56740f8e99fe4bf5b43e7fd7db75d678a7273dd418060b610e60185cc20Virustotal results 12.07%Ransomware.Hive
2022-02-15n/aexe 5a2a01a909f8ad20484259c2e305c24791ea8fff7adc3f63f927440e2d14928cn/a Ransomware.Hive
2022-02-08n/aexe 15d06d1741cc8b5495da9c79c6f630e33060e80c73da9666500f6f0bdf5ff259Virustotal results 47.14%Ransomware.Hive